CVE-2022-3286: Medium severity gitlab vulnerability
Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3286?
CVE-2022-3286 is categorized as a high-severity vulnerability due to its potential to bypass IP address restrictions in GitLab EE.
How do I fix CVE-2022-3286?
To fix CVE-2022-3286, upgrade GitLab EE to version 15.2.5, 15.3.4, or 15.4.1 or later.
Which versions of GitLab are affected by CVE-2022-3286?
CVE-2022-3286 affects GitLab EE versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1.
What is the impact of CVE-2022-3286?
The impact of CVE-2022-3286 allows unauthorized group members to bypass established IP address restrictions using a deploy token.
Is user authentication affected by CVE-2022-3286?
CVE-2022-3286 does not directly affect user authentication but allows bypassing IP restrictions, potentially compromising security.