Medium severity5.3NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026
CVE-2022-3482
CVE-2022-3482
Description
An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allowed an unauthorized user to see release names even when releases we set to be restricted to project members only
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 4 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.3.0,<15.4.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.3.0,<15.4.6
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:15.6.0:*:*:*:enterprise:*:*:*
- (no CPE)range: >=11.3, <15.4.6
- Range: from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/gitlab/-/issues/377802nvdExploitVendor Advisory
- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3482.jsonnvdVendor Advisory
- hackerone.com/reports/1725841nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.