Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-1936
HistoryJun 06, 2022 - 12:00 a.m.

CVE-2022-1936

2022-06-0600:00:00
ubuntu.com
ubuntu.com
17
gitlab ee
incorrect authorization
cve-2022-1936
project deploy token
ip address restrictions
unix

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

22.7%

Incorrect authorization in GitLab EE affecting all versions from 12.0
before 14.9.5, all versions starting from 14.10 before 14.10.4, all
versions starting from 15.0 before 15.0.1 allowed an attacker already in
possession of a valid Project Deploy Token to misuse it from any location
even when IP address restrictions were configured

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

22.7%