VulnerabilityModified
CVE-2022-3758
Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.
MEDIUM 5.4EPSS 0.58%
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3758.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/379598Broken Link
- https://hackerone.com/reports/1751258Permissions Required
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3758.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/379598Broken Link
- https://hackerone.com/reports/1751258Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.