Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2022-3483
Published: November 7, 2022
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote administrator can exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2022-3483
GitLab Enterprise Edition - addressed in versions 15.3.5, 15.4.4, 15.5.2