VYPR
Medium severity5.9NVD Advisory· Published Aug 5, 2022· Updated Jun 17, 2026

CVE-2022-2501

CVE-2022-2501

Description

An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.

Affected products

6
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.0.0,<15.0.5
    • cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*
    • (no CPE)range: from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1
    • (no CPE)range: >=12.0, <15.0.5
  • Range: from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1
  • osv-coords
    Range: >= 12.0.0, < 15.0.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.