Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2501


An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.


Published

2022-08-05T16:15:12.327

Last Modified

2024-11-21T07:01:07.613

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.0.5 Yes
Application gitlab gitlab < 15.1.4 Yes
Application gitlab gitlab 15.2 Yes

References