Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-1983
HistoryJul 01, 2022 - 4:15 p.m.

Authorization

2022-07-0116:15:00
PRIOn knowledge base
www.prio-n.com
2
gitlab ee
incorrect authorization
attacker misuse
deploy key
deploy token
container registries
ip restrictions

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

22.7%

Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any location to access Container Registries even when IP address restrictions were configured.

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

22.7%