CVE-2022-3285: High severity gitlab vulnerability
Published Nov 9, 2022
·Updated
Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab
Affected Software
6 affected components
GitLab GitLab>=12.0.0<15.2.5
GitLab GitLab>=12.0.0<15.2.5
GitLab GitLab>=15.3.0<15.3.4
GitLab GitLab>=15.3.0<15.3.4
GitLab GitLab=15.4.0
GitLab GitLab=15.4.0
Event History
Nov 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3285?
CVE-2022-3285 has a medium severity rating as it allows unauthorized users to access the healthcheck endpoint.
2
How do I fix CVE-2022-3285?
To fix CVE-2022-3285, upgrade GitLab to versions 15.2.5, 15.3.4, or 15.4.1 or later.
3
Which versions are affected by CVE-2022-3285?
CVE-2022-3285 affects all GitLab versions from 12.0 up to but not including 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
4
What type of attack can CVE-2022-3285 enable?
CVE-2022-3285 enables an unauthorized attacker to potentially disrupt access to the GitLab service.
5
Is CVE-2022-3285 specific to any edition of GitLab?
No, CVE-2022-3285 affects both the community and enterprise editions of GitLab.