PT-2022-13253 · Gitlab · Gitlab Ce/Ee+1

Dominic Couture

·

Published

2022-03-28

·

Updated

2024-03-06

·

CVE-2022-0549

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 14.3.6 GitLab CE/EE versions 14.4.0 through 14.4.3 GitLab CE/EE versions 14.5.0 through 14.5.1
Description An issue has been discovered in GitLab CE/EE that allows unprivileged users to add other users to groups through the GitLab REST API under certain conditions, even if this action is not possible through the Web UI.
Recommendations For versions prior to 14.3.6, update to version 14.3.6 or later. For versions 14.4.0 through 14.4.3, update to version 14.4.4 or later. For versions 14.5.0 through 14.5.1, update to version 14.5.2 or later.

Exploit

Fix

Related Identifiers

BIT-GITLAB-2022-0549
CVE-2022-0549

Affected Products

Gitlab
Gitlab Ce/Ee