Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-3325
HistoryOct 17, 2022 - 12:00 a.m.

CVE-2022-3325

2022-10-1700:00:00
ubuntu.com
ubuntu.com
17
gitlab ce/ee
api
access control
unauthorized editing

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

22.7%

Improper access control in the GitLab CE/EE API affecting all versions
starting from 12.8 before 15.2.5, all versions starting from 15.3 before
15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing
the approval rules via the API by an unauthorised user.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

22.7%