Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3285


Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab


Published

2022-11-09T23:15:14.013

Last Modified

2024-11-21T07:19:13.177

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.2.5 Yes
Application gitlab gitlab < 15.2.5 Yes
Application gitlab gitlab < 15.3.4 Yes
Application gitlab gitlab < 15.3.4 Yes
Application gitlab gitlab 15.4.0 Yes
Application gitlab gitlab 15.4.0 Yes

References