Security Advisory

CVE-2022-3286

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-10-17 00:00:00
Last updated 2025-05-13 15:45:08
Assigner GitLab
CVSS score 5.3
State PUBLISHED

Description

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token