GitLab CE/EE Access Token Leakage Vulnerability (CVE-2022-2882)

The advisory details a GitLab CE/EE vulnerability (CVE‑2022‑2882) that allows authenticated attackers to modify integration URLs and steal GitHub integration access tokens, lists affected versions across community and enterprise editions, and recommends upgrading to specific patched releases.

Laravel Tech Community
Laravel Tech Community
Laravel Tech Community
GitLab CE/EE Access Token Leakage Vulnerability (CVE-2022-2882)

GitLab CE/EE is an integrated software development platform based on Git. A sensitive information leakage vulnerability exists in certain versions, where an authenticated attacker (e.g., a maintainer) can modify the integration URL to send authenticated requests to a server under the attacker’s control, thereby obtaining the GitHub integration access token.

Vulnerability Name

GitLab Access Token Leakage Vulnerability

Vulnerability Type

Exposing resources to the wrong scope

Discovery Date

2022-10-29

Impact Breadth

Wide

MPS Number

MPS-2022-55621

CVE Number

CVE-2022-2882

CNVD Number

-

The vulnerability affects all versions of GitLab. Specific affected ranges include:

GitLab Community: versions <15.4, ≥15.4.1

GitLab Community: versions ≥15.4 and <15.4.1

GitLab Community: versions ≥15.3 and <15.3.4

GitLab Community: versions ≥12.6 and <15.2.5

GitLab Enterprise: versions ≥15.3 and <15.3.4

GitLab Enterprise: versions ≥12.6 and <15.2.5

GitLab Enterprise: versions ≥15.4 and <15.4.1

Remediation steps are to upgrade the affected components to patched versions:

Upgrade GitLab Community to version 15.2.5 or later.

Upgrade GitLab Enterprise to version 15.3.4 or later.

Upgrade GitLab Enterprise to version 15.2.5 or later.

Upgrade GitLab Enterprise to version 15.4.1 or later.

Upgrade GitLab Community to version 15.3.4 or later.

Upgrade GitLab Community to version 15.4.1 or later.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

GitLabVulnerabilitycve-2022-2882information-securityaccess-token
Laravel Tech Community
Written by

Laravel Tech Community

Specializing in Laravel development, we continuously publish fresh content and grow alongside the elegant, stable Laravel framework.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.