CVE-2022-2512
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.
Summary dbcve.org
In affected GitLab versions, when a user is removed from a project, their TODO items referencing confidential notes are not properly invalidated. This allows former project members to continue receiving TODO notifications about confidential notes they should no longer have access to, resulting in unauthorized information disclosure.
Mitigation
Upgrade GitLab to version 15.0.5, 15.1.4, 15.2.1, or later to receive the patch that properly invalidates TODO items for confidential notes when membership is revoked.