Information Security 3 min read

GitLab CE/EE Access Token Leakage Vulnerability (CVE-2022-2882)

The advisory details a GitLab CE/EE vulnerability (CVE‑2022‑2882) that allows authenticated attackers to modify integration URLs and steal GitHub integration access tokens, lists affected versions across community and enterprise editions, and recommends upgrading to specific patched releases.

Laravel Tech Community
Laravel Tech Community
Laravel Tech Community
GitLab CE/EE Access Token Leakage Vulnerability (CVE-2022-2882)

GitLab CE/EE is an integrated software development platform based on Git. A sensitive information leakage vulnerability exists in certain versions, where an authenticated attacker (e.g., a maintainer) can modify the integration URL to send authenticated requests to a server under the attacker’s control, thereby obtaining the GitHub integration access token.

Vulnerability Name

GitLab Access Token Leakage Vulnerability

Vulnerability Type

Exposing resources to the wrong scope

Discovery Date

2022-10-29

Impact Breadth

Wide

MPS Number

MPS-2022-55621

CVE Number

CVE-2022-2882

CNVD Number

-

The vulnerability affects all versions of GitLab. Specific affected ranges include:

GitLab Community: versions <15.4, ≥15.4.1

GitLab Community: versions ≥15.4 and <15.4.1

GitLab Community: versions ≥15.3 and <15.3.4

GitLab Community: versions ≥12.6 and <15.2.5

GitLab Enterprise: versions ≥15.3 and <15.3.4

GitLab Enterprise: versions ≥12.6 and <15.2.5

GitLab Enterprise: versions ≥15.4 and <15.4.1

Remediation steps are to upgrade the affected components to patched versions:

Upgrade GitLab Community to version 15.2.5 or later.

Upgrade GitLab Enterprise to version 15.3.4 or later.

Upgrade GitLab Enterprise to version 15.2.5 or later.

Upgrade GitLab Enterprise to version 15.4.1 or later.

Upgrade GitLab Community to version 15.3.4 or later.

Upgrade GitLab Community to version 15.4.1 or later.

GitLabinformation securityvulnerabilityaccess tokencve-2022-2882
Laravel Tech Community
Written by

Laravel Tech Community

Specializing in Laravel development, we continuously publish fresh content and grow alongside the elegant, stable Laravel framework.

0 followers
Reader feedback

How this landed with the community

login Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.