{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "12.6"
              },
              {
                "fixed": "15.3.5"
              }
            ]
          },
          "events": [
            {
              "introduced": "11ac4a9aa216b39b2880f8a647f39f6ea77cef1a"
            },
            {
              "fixed": "96db1338fc67d37c6d4f9e346d7847bda8605c76"
            }
          ],
          "repo": "https://gitlab.com/gitlab-org/gitlab",
          "type": "GIT"
        },
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "15.4"
              },
              {
                "fixed": "15.4.4"
              }
            ]
          },
          "events": [
            {
              "introduced": "abbda55531f0a9d630eee1dcf2305ca499c94116"
            },
            {
              "fixed": "1605b0f6c099e11e1335568bc4105de5c5d2a19c"
            }
          ],
          "repo": "https://gitlab.com/gitlab-org/gitlab",
          "type": "GIT"
        },
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "15.5"
              },
              {
                "fixed": "15.5.2"
              }
            ]
          },
          "events": [
            {
              "introduced": "af0fced4dd2e767d361f2bdc0732be15ad2c1026"
            },
            {
              "fixed": "767831e030c7b8b413b453d4730e92199ab7cfa3"
            }
          ],
          "repo": "https://gitlab.com/gitlab-org/gitlab",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "GitLab",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3793.json"
  },
  "details": "An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to read variables set directly in a GitLab CI/CD configuration file they don't have access to.",
  "id": "CVE-2022-3793",
  "modified": "2026-04-01T23:09:39.829689346Z",
  "published": "2022-11-09T00:00:00Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3793.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3793.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3793"
    },
    {
      "type": "REPORT",
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/372120"
    }
  ],
  "schema_version": "1.7.3",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}