PT-2022-12979 · Gitlab · Gitlab

Joaxcaron

·

Published

2022-01-18

·

Updated

2024-03-06

·

CVE-2022-0125

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 12.0 through 14.4.5 GitLab versions 14.5.0 through 14.5.3 GitLab versions 14.6.0 through 14.6.2
Description An issue has been discovered in GitLab where it was not verifying that a maintainer of a project had the right access to import members from a target project.
Recommendations For versions 12.0 through 14.4.5, update to version 14.4.5 or later. For versions 14.5.0 through 14.5.3, update to version 14.5.3 or later. For versions 14.6.0 through 14.6.2, update to version 14.6.2 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-0125
CVE-2022-0125

Affected Products

Gitlab