PT-2022-16742 · Gitlab · Gitlab Ce/Ee+1

Justas_Bon

·

Published

2022-08-05

·

Updated

2024-03-06

·

CVE-2022-2459

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions prior to 15.0.5 GitLab EE versions 15.1 through 15.1.4 GitLab EE versions 15.2 through 15.2.1
Description An issue has been discovered in GitLab EE where email invited members may be able to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.
Recommendations For versions prior to 15.0.5, update to version 15.0.5 or later. For versions 15.1 through 15.1.4, update to version 15.1.4 or later. For versions 15.2 through 15.2.1, update to version 15.2.1 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2022-2459
CVE-2022-2459

Affected Products

Gitlab
Gitlab Ce/Ee