Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-3820: 2022/CVE-2022-3820.json · master · GitLab.org / cves · GitLab

An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not performing correct authentication with some Package Registries when IP address restrictions were configured, allowing an attacker already in possession of a valid Deploy Token to misuse it from any location.

CVE
#js#git#auth

Skip to content

GitLab

Next

    • GitLab: the DevOps platform
    • Explore GitLab
    • Install GitLab
    • How GitLab compares
    • Get started
    • GitLab docs
    • GitLab Learn
  • Pricing

  • Talk to an expert

  • /

  • Help

    • Help

    • Support

    • Community forum

    • Submit feedback

    • Contribute to GitLab

    Projects Groups Snippets

  • Sign up now

  • Login

  • Sign in / Register

  • GitLab.org
  • cves
  • Repository

Switch branch/tag

  • cves
  • 2022
  • CVE-2022-3820.json

Find file BlameHistoryPermalink

  • Publishing 0 updated advisories and 2 new advisories · 6cf4af7e

    🤖 GitLab Bot 🤖 authored Jan 20, 2023

    6cf4af7e

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907