MEDIUM
CVE-2022-1999
CVSS
5.3
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.
Summary dbcve.org
GitLab CE/EE contains a broken access control vulnerability in its REST API where an unprivileged user (such as a guest or basic user) could modify label descriptions that should be restricted to higher-privileged users. This represents an authorization bypass allowing unauthorized modification of project metadata.
Mitigation
Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later. Alternatively, restrict API access and audit existing user permissions until the upgrade can be completed.
EPSS Score
0.65%
Probability of exploitation in next 30 days
49.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.