CVE-2022-4167 MEDIUM

CVE-2022-4167

Vendor Gitlab
Product GitLab
Published January 12, 2023
Last update April 8, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.

Key dates

02Disclosure timeline

January 12, 2023 CVE published
April 8, 2025 Record updated