Loading HuntDB...

GHSA-9672-4fh3-mcfg

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Developers to view the project's Audit Events and Developers or Maintainers to view the group's Audit Events. These should have been restricted to Project Maintainers, Group Owners, and above.

Related CVEs

Key Information

GHSA ID
GHSA-9672-4fh3-mcfg
Published
November 10, 2022 12:01 PM
Last Modified
November 11, 2022 12:00 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 16, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.