CVE-2022-3740: Medium severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3740?
CVE-2022-3740 is considered a medium severity vulnerability due to its potential to allow unauthorized access to sensitive resources.
How do I fix CVE-2022-3740?
To fix CVE-2022-3740, upgrade GitLab to version 15.3.5, 15.4.4, or 15.5.2 or later.
Which versions of GitLab are affected by CVE-2022-3740?
CVE-2022-3740 affects GitLab CE/EE versions from 12.9 up to 15.4.6, including certain versions of 15.5.
Who is impacted by CVE-2022-3740?
Group owners using affected versions of GitLab with External Authorization enabled may be impacted by CVE-2022-3740.
What should I do if I can't immediately upgrade due to CVE-2022-3740?
If upgrading is not possible, consider implementing workarounds for External Authorization checks to mitigate potential risks associated with CVE-2022-3740.