MEDIUM

CVE-2022-2539

Gitlab GitLab 2022-08-05 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization.

Summary dbcve.org

An authorization bypass in GitLab CE/EE versions 14.6 through 15.2.1 allowed project members to filter issues by contact and organization fields, exposing sensitive information that should have been restricted based on project membership access controls.

Mitigation

Upgrade GitLab to version 15.0.5, 15.1.4, 15.2.1 or later to patch the broken access control that permitted unauthorized filtering of issue metadata.

EPSS Score

0.71%
Probability of exploitation in next 30 days
52.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE