Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2023-01-12T00:00:00

Updated: 2024-08-03T01:34:48.801Z

Reserved: 2022-11-28T00:00:00

Link: CVE-2022-4167

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-01-12T04:15:10.327

Modified: 2023-01-18T20:32:21.293

Link: CVE-2022-4167

cve-icon Redhat

No data.