CVE-2022-2303 is a medium-severity vulnerability affecting GitLab CE/EE versions prior to 15.0.5, 15.1.4, and 15.2.1. It allows group members to bypass group-level 2FA enforcement by utilizing the Resource Owner Password Credentials grant to obtain an access token without requiring two-factor authentication. The CVSS score of 4.3 indicates a low-impact vulnerability with low attack complexity, potentially leading to a loss of integrity (I:L) but no confidentiality or availability impact (C:N, A:N). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.1.0, < 15.1.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
15.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:* | ||
< 15.0.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.1.0, < 15.1.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.