CVE-2022-3413
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.
La autorización incorrecta durante la visualización de eventos de auditoría en GitLab EE que afecta a todas las versiones desde 14.5 anterior a 15.3.5, 15.4 anterior a 15.4.4 y 15.5 anterior a 15.5.2, permitió a los desarrolladores ver los eventos de auditoría del proyecto y a los desarrolladores o mantenedores ver los Eventos de Auditoría del grupo. Estos deberían haber estado restringidos a mantenedores de proyectos, propietarios de grupos y superiores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-07 CVE Reserved
- 2022-11-09 CVE Published
- 2024-06-01 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3413.json | 2023-08-08 | |
https://gitlab.com/gitlab-org/gitlab/-/issues/374926 | 2023-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.5.0 < 15.3.5 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.5.0 < 15.3.5" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 15.4.0 < 15.4.4 Search vendor "Gitlab" for product "Gitlab" and version " >= 15.4.0 < 15.4.4" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 15.5.0 < 15.5.2 Search vendor "Gitlab" for product "Gitlab" and version " >= 15.5.0 < 15.5.2" | enterprise |
Affected
|