Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42715 | Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. Allowed for editing the approval rules via the API by an unauthorised user. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 13 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-05-13T15:37:11.798Z
Reserved: 2022-09-26T00:00:00.000Z
Link: CVE-2022-3325
Updated: 2024-08-03T01:07:06.549Z
Status : Modified
Published: 2022-10-17T16:15:22.687
Modified: 2025-05-13T16:15:22.107
Link: CVE-2022-3325
No data.
OpenCVE Enrichment
No data.
EUVD