Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2022-2882
Published: October 3, 2022
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote administrator can modify the integration URL such that authenticated requests are sent to an attacker controlled server and exfiltrate a GitHub integration's access token.