MEDIUM

CVE-2022-2512

Gitlab GitLab 2022-08-05 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.

Summary dbcve.org

In affected GitLab versions, when a user is removed from a project, their TODO items referencing confidential notes are not properly invalidated. This allows former project members to continue receiving TODO notifications about confidential notes they should no longer have access to, resulting in unauthorized information disclosure.

Mitigation

Upgrade GitLab to version 15.0.5, 15.1.4, 15.2.1, or later to receive the patch that properly invalidates TODO items for confidential notes when membership is revoked.

EPSS Score

0.86%
Probability of exploitation in next 30 days
57th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE