Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2501
HistoryAug 05, 2022 - 4:15 p.m.

Improper access control

2022-08-0516:15:00
PRIOn knowledge base
www.prio-n.com
3
improper access control
gitlab ee
version 12.0
version 15.2.1
ip allow-listing
artifacts.

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

53.0%

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

53.0%