CVE-2022-4037: Race Condition
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4037?
CVE-2022-4037 has been classified with a high severity due to its potential for verified email forgery and third-party account takeover.
How do I fix CVE-2022-4037?
To fix CVE-2022-4037, update GitLab to version 15.5.7, 15.6.4, or 15.7.2 or later.
What versions of GitLab are affected by CVE-2022-4037?
CVE-2022-4037 affects all versions of GitLab before 15.5.7 and all versions starting from 15.6 up to 15.6.4 and from 15.7 up to 15.7.2.
What type of vulnerability is CVE-2022-4037?
CVE-2022-4037 is a race condition vulnerability that can lead to account takeover.
What impact does CVE-2022-4037 have on users?
The impact of CVE-2022-4037 includes the possibility of unauthorized access to user accounts through email forgery.