PT-2022-17043 · Gitlab · Gitlab Ce/Ee+1

Joaxcar

·

Published

2022-08-05

·

Updated

2024-03-06

·

CVE-2022-2501

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions prior to 15.0.5 GitLab EE versions 15.1 prior to 15.1.4 GitLab EE versions 15.2 prior to 15.2.1
Description The issue is related to improper access control, allowing an attacker to bypass IP allow-listing and download artifacts, although proper permissions are still required for the attack to be successful.
Recommendations For GitLab EE versions prior to 15.0.5, update to version 15.0.5 or later. For GitLab EE versions 15.1 prior to 15.1.4, update to version 15.1.4 or later. For GitLab EE versions 15.2 prior to 15.2.1, update to version 15.2.1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-2501
CVE-2022-2501

Affected Products

Gitlab
Gitlab Ce/Ee