CVE-2022-3285

MEDIUM

GitLab <15.2.5-15.4.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0034
EPSS Percentile 57.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (2)
gitlab/gitlab 15.4.0 (2 CPE variants)
gitlab/gitlab 12.0.0 - 15.2.5 (2 CPE variants)
Published Nov 09, 2022
Tracked Since Feb 18, 2026