Medium severity4.3NVD Advisory· Published Aug 5, 2022· Updated Jun 17, 2026
CVE-2022-2303
CVE-2022-2303
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <15.0.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <15.0.5
- cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*
- (no CPE)range: <15.0.5, 15.1<15.1.4, 15.2<15.2.1
- (no CPE)range: >=15.2, <15.2.1
- Range: <15.0.5, 15.1<15.1.4, 15.2<15.2.1
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2303.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/355028nvdBroken LinkVendor Advisory
- hackerone.com/reports/1498133nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.