CVE-2022-3483: Medium severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions starting from 15.4 before 15.4.4, all versions starting from 15.5 before 15.5.2. A malicious maintainer could exfiltrate a Datadog integration's access token by modifying the integration URL such that authenticated requests are sent to an attacker controlled server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3483?
The severity of CVE-2022-3483 is medium, with a CVSS score of 5.4.
Which versions of GitLab CE/EE are affected by CVE-2022-3483?
All versions of GitLab CE/EE starting from 12.1 before 15.3.5, 15.4 before 15.4.4, and 15.5 before 15.5.2 are affected by CVE-2022-3483.
What is the issue with CVE-2022-3483?
CVE-2022-3483 allows a malicious maintainer to exfiltrate a Datadog integration's access token by modifying the integration.
How can I fix CVE-2022-3483?
To fix CVE-2022-3483, it is recommended to upgrade to GitLab CE/EE version 15.3.5, 15.4.4, or 15.5.2 or later.
Where can I find more information about CVE-2022-3483?
More information about CVE-2022-3483 can be found in the GitLab CVE JSON file and the related GitLab and HackerOne links.