Medium severity6.5NVD Advisory· Published Oct 17, 2022· Updated Jun 17, 2026
CVE-2022-3067
CVE-2022-3067
Description
An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an authenticated user to read arbitrary projects' content given the project's ID.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=14.4,<15.2.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=14.4,<15.2.5
- (no CPE)range: 14.4 <= v < 15.2.5, 15.3 <= v < 15.3.4, 15.4 <= v < 15.4.1
- (no CPE)range: >=15.4, <15.4.1
- Range: 14.4 <= v < 15.2.5, 15.3 <= v < 15.3.4, 15.4 <= v < 15.4.1
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3067.jsonnvdThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/372165nvdBroken LinkThird Party Advisory
- hackerone.com/reports/1685822nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.