MEDIUM
CVE-2022-2539
CVSS
5.3
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization.
Summary dbcve.org
An authorization bypass in GitLab CE/EE versions 14.6 through 15.2.1 allowed project members to filter issues by contact and organization fields, exposing sensitive information that should have been restricted based on project membership access controls.
Mitigation
Upgrade GitLab to version 15.0.5, 15.1.4, 15.2.1 or later to patch the broken access control that permitted unauthorized filtering of issue metadata.
EPSS Score
0.71%
Probability of exploitation in next 30 days
52.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.