An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/372149 | third party advisory broken link |
https://hackerone.com/reports/1685105 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3066.json | third party advisory |