CVE-2022-3285: GitLab
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an unauthorized attacker to prevent access to GitLab
Affected products
- GitLab GitLab: from 12.0.0, before 15.2.5 (fixed in 15.2.5); from 15.3.0, before 15.3.4 (fixed in 15.3.4); version 15.4.0 only
Published 2022-11-09. Last modified 2026-06-17.