Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2022-2882
Published: October 3, 2022
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote administrator can modify the integration URL such that authenticated requests are sent to an attacker controlled server and exfiltrate a GitHub integration's access token.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2022-2882
GitLab Enterprise Edition - addressed in versions 15.2.5, 15.3.4, 15.4.1