CVE-2022-2326
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.
Summary dbcve.org
GitLab allows users to add secondary email addresses to their account. The vulnerability allows an attacker to add another user's primary email as an unverified secondary email to their own account, then use that email address to accept an invitation to a private project, thereby gaining unauthorized access to that private project.
Mitigation
Upgrade GitLab to version 15.0.5, 15.1.4, 15.2.1 or later. Review existing project memberships and invitations for suspicious activity.