Gitlab · Gitlab · CVE-2022-0154
**Name of the Vulnerable Software and Affected Versions**
GitLab versions 7.7 through 14.4.4
GitLab versions 14.5.0 through 14.5.2
GitLab versions 14.6.0 through 14.6.1
**Description**
The issue allows a malicious user to perform a Cross-Site Request Forgery attack, enabling them to import their GitHub project into another GitLab user's account.
**Recommendations**
For GitLab versions 7.7 through 14.4.4, update to version 14.4.5 or later.
For GitLab versions 14.5.0 through 14.5.2, update to version 14.5.3 or later.
For GitLab versions 14.6.0 through 14.6.1, update to version 14.6.2 or later.