CVE-2022-1983

MEDIUM

GitLab EE <14.10.5-15.0.4-15.1.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured.

References (2)

Core 2
Core References

Scores

CVSS v3 6.5
EPSS 0.0013
EPSS Percentile 32.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-863
Status published
Products (2)
gitlab/gitlab 15.1.0
gitlab/gitlab 10.7.0 - 14.10.5
Published Jul 01, 2022
Tracked Since Feb 18, 2026