VYPR
Medium severity6.4NVD Advisory· Published Jan 12, 2023· Updated Jun 17, 2026

CVE-2022-4037

CVE-2022-4037

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

Affected products

6
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <15.5.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <15.5.7
    • (no CPE)range: <15.5.7, >=15.6 <15.6.4, >=15.7 <15.7.2
    • (no CPE)range: >=0.0, <15.5.7
  • Range: <15.5.7, >=15.6 <15.6.4, >=15.7 <15.7.2
  • osv-coords
    Range: < 15.5.7

Patches

Vulnerability mechanics

References

3

News mentions

1