Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-4167


Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.


Published

2023-01-12T04:15:10.327

Last Modified

2025-04-08T17:15:33.827

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-863
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 15.5.7 Yes
Application gitlab gitlab < 15.6.4 Yes
Application gitlab gitlab < 15.7.2 Yes

References