CVE-2022-3482: Medium severity gitlab vulnerability
An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3482?
The severity of CVE-2022-3482 is medium.
What is the impact of CVE-2022-3482?
CVE-2022-3482 allows an unauthorized user to see release names even when releases are set to be restricted to project members only.
How does CVE-2022-3482 affect GitLab CE/EE?
CVE-2022-3482 affects all versions of GitLab CE/EE from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2.
Is there a fix for CVE-2022-3482?
Yes, GitLab has released a fix for CVE-2022-3482. Users should update to version 15.3.5, 15.4.4, or 15.5.2 or later to mitigate the vulnerability.
Where can I find more information about CVE-2022-3482?
You can find more information about CVE-2022-3482 on the GitLab website and HackerOne.