CVE-2022-2303

MEDIUM

GitLab CE/EE <15.0.5, <15.1.4, <15.2.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

References (3)

Core 3
Core References
Broken Link, Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab/-/issues/355028
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1498133

Scores

CVSS v3 4.3
EPSS 0.0017
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-287
Status published
Products (2)
gitlab/gitlab 15.2 (2 CPE variants)
gitlab/gitlab < 15.0.5 (2 CPE variants)
Published Aug 05, 2022
Tracked Since Feb 18, 2026