CVE-2022-4037 PUBLISHED

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

EPSS 0.58% · 68.8th percentile

Risk Scores

EPSS Score
0.58%
68.8th percentile

Affected Products

VendorProductVersions
Bitnamigitlab0, 15.6.0, 15.7.0
Bitnamigitlab0, 15.6.0, 15.7.0

Timeline

References

Open in Interactive Console →