CVE-2022-1428
Status: ModifiedMedium (4.3)—
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.66%
- Percentile among all scored CVEs: 50
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-770
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-1428",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@gitlab.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@gitlab.com",
"affectedData": [
{
"vendor": "GitLab",
"product": "GitLab",
"versions": [
{
"status": "affected",
"version": "<14.8.6"
},
{
"status": "affected",
"version": ">=14.9, <14.9.4"
},
{
"status": "affected",
"version": ">=14.10, <14.10.1"
}
]
}
]
}
],
"published": "2022-05-11T15:15:08.960",
"references": [
{
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1428.json",
"tags": [
"Vendor Advisory"
],
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/342481",
"tags": [
"Broken Link"
],
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1428.json",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/342481",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced."
},
{
"lang": "es",
"value": "Se ha detectado un problema en GitLab afectando a todas las versiones anteriores a 14.8.6, a todas las versiones a partir de la 14.9 anteriores a 14.9.4 y todas las versiones a partir de la 14.10 anteriores a 14.10.1. GitLab estaba verificando incorrectamente los límites de estrangulamiento para las peticiones de paquetes autenticados, lo que provocaba que los límites no se aplicaran"
}
],
"lastModified": "2026-06-17T04:22:26.140",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6BEDF75-ACB0-4243-BDB8-B855CC160CB1",
"versionEndExcluding": "14.8.6"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3780334-BD2E-44EE-83BE-144B45F8F722",
"versionEndExcluding": "14.8.6"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCD83B23-0868-4545-9E4E-98F0DF151924",
"versionEndExcluding": "14.9.4",
"versionStartIncluding": "14.9.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B4C393E-6B88-4AF8-9071-2C43935A1AEC",
"versionEndExcluding": "14.9.4",
"versionStartIncluding": "14.9.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41411D82-66AE-4AE4-9093-D019F80ED990"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:14.10.0:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9643D908-345C-48F9-BEDE-08F69EC16931"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@gitlab.com"
}