CVE-2022-3740
https://notcve.org/view.php?id=CVE-2022-3740
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys . • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3740.json https://gitlab.com/gitlab-org/gitlab/-/issues/368416 https://hackerone.com/reports/1602904 •
CVE-2022-2907
https://notcve.org/view.php?id=CVE-2022-2907
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2907.json https://gitlab.com/gitlab-org/gitlab/-/issues/349388 https://hackerone.com/reports/1417680 •
CVE-2022-3613
https://notcve.org/view.php?id=CVE-2022-3613
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. Una consulta del servidor Prometheus manipulada puede provocar un alto consumo de recursos y provocar una denegación de servicio. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3613.json https://gitlab.com/gitlab-org/gitlab/-/issues/378456 https://hackerone.com/reports/1723106 •
CVE-2022-3870
https://notcve.org/view.php?id=CVE-2022-3870
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility. Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde 10.0 anteriores a 15.5.7, todas las versiones desde 15.6 anteriores a 15.6.4, todas las versiones desde 15.7 anteriores a 15.7.2. GitLab permite a los usuarios no autenticados descargar avatares de usuario utilizando la identificación de usuario de la víctima, en instancias privadas que restringen la visibilidad a nivel público. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3870.json https://gitlab.com/gitlab-org/gitlab/-/issues/381647 https://hackerone.com/reports/1753423 •
CVE-2022-4167
https://notcve.org/view.php?id=CVE-2022-4167
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them. La verificación de autorización incorrecta que afecta a todas las versiones de GitLab EE desde la 13.11 anterior a la 15.5.7, la 15.6 anterior a la 15.6.4 y la 15.7 anterior a la 15.7.2 permite que los tokens de acceso al grupo sigan funcionando incluso después de que el propietario del grupo pierda la capacidad de revocarlos. • https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4167.json https://gitlab.com/gitlab-org/gitlab/-/issues/367740 • CWE-863: Incorrect Authorization •