4.3
CVSSv3

CVE-2022-2303

Published: 05/08/2022 Updated: 08/08/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue has been discovered in GitLab CE/EE affecting all versions prior to 15.0.5, all versions starting from 15.1 prior to 15.1.4, all versions starting from 15.2 prior to 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

gitlab gitlab 15.2

Vendor Advisories

Severity Unknown Remote Unknown Type Unknown Description AVG-2785 gitlab 1520-1 1521-1 Medium Vulnerable ...