MEDIUM

CVE-2022-1999

Gitlab GitLab 2022-07-01 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.

Summary dbcve.org

GitLab CE/EE contains a broken access control vulnerability in its REST API where an unprivileged user (such as a guest or basic user) could modify label descriptions that should be restricted to higher-privileged users. This represents an authorization bypass allowing unauthorized modification of project metadata.

Mitigation

Upgrade GitLab to version 14.10.5, 15.0.4, 15.1.1 or later. Alternatively, restrict API access and audit existing user permissions until the upgrade can be completed.

EPSS Score

0.65%
Probability of exploitation in next 30 days
49.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE