CVE-2022-2501: High severity gitlab vulnerability
An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2501?
CVE-2022-2501 is rated as a high severity vulnerability due to its potential to allow unauthorized access to sensitive artifacts.
How do I fix CVE-2022-2501?
To fix CVE-2022-2501, upgrade your GitLab instance to version 15.0.5, 15.1.4, or 15.2.1 or later.
Which versions of GitLab are affected by CVE-2022-2501?
CVE-2022-2501 affects GitLab EE versions from 12.0 up to, but not including, 15.0.5, 15.1 up to 15.1.4, and 15.2 up to 15.2.1.
What kind of attack does CVE-2022-2501 facilitate?
CVE-2022-2501 allows an attacker to bypass IP allow-listing and download artifacts, provided they have proper permissions.
Is CVE-2022-2501 a critical vulnerability that requires immediate attention?
Yes, due to its potential exploitability, CVE-2022-2501 requires immediate attention to ensure security and integrity of data.