Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.
History

Tue, 08 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2025-04-08T16:28:42.595Z

Reserved: 2022-11-28T00:00:00.000Z

Link: CVE-2022-4167

cve-icon Vulnrichment

Updated: 2024-08-03T01:34:48.801Z

cve-icon NVD

Status : Modified

Published: 2023-01-12T04:15:10.327

Modified: 2025-04-08T17:15:33.827

Link: CVE-2022-4167

cve-icon Redhat

No data.