HIGH

CVE-2022-2326

Gitlab GitLab 2022-08-05 CVSS v3.1
CVSS
8.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.

Summary dbcve.org

GitLab allows users to add secondary email addresses to their account. The vulnerability allows an attacker to add another user's primary email as an unverified secondary email to their own account, then use that email address to accept an invitation to a private project, thereby gaining unauthorized access to that private project.

Mitigation

Upgrade GitLab to version 15.0.5, 15.1.4, 15.2.1 or later. Review existing project memberships and invitations for suspicious activity.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.82%
Probability of exploitation in next 30 days
55.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE