Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-4143


An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization


Published

2023-06-28T21:15:09.290

Last Modified

2024-11-21T07:34:39.557

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.8.5 Yes
Application gitlab gitlab < 15.8.5 Yes
Application gitlab gitlab < 15.9.4 Yes
Application gitlab gitlab < 15.9.4 Yes
Application gitlab gitlab 15.10.0 Yes
Application gitlab gitlab 15.10.0 Yes

References