Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2022-2497
Published: July 29, 2022
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote administrator can exfiltrate an integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.
Affected software
GitLab Enterprise Edition
IBM Aspera Faspex for Linux
IBM Aspera Faspex for Windows
How to mitigate CVE-2022-2497
GitLab Enterprise Edition - addressed in versions 15.0.5, 15.1.4, 15.2.1
IBM Aspera Faspex for Linux - addressed in versions 4.4.1 PL 12, 5.0.1
IBM Aspera Faspex for Windows - update to 4.4.1 PL 12