An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/377802 | exploit vendor advisory |
https://hackerone.com/reports/1725841 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3482.json | vendor advisory |