CVE-2022-3740 is a bypass vulnerability in GitLab CE/EE, affecting versions 12.9 through 15.3.4, 15.4 through 15.4.3, and 15.5 through 15.5.1. A group owner can bypass External Authorization checks to access git repositories and package registries using Deploy tokens or Deploy keys. This vulnerability is rated Medium severity (CVSS 4.9) with a low attack complexity and no user interaction required, but it necessitates high privileges (PR:H). The primary impact is a high confidentiality risk (C:H), allowing unauthorized access to sensitive data within repositories and registries. There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.9.0, < 15.4.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 12.9.0, < 15.4.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 15.5.0, < 15.5.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 15.5.0, < 15.5.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
15.6.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.