CVE-2022-1783

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 06:41

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json - Patch, Third Party Advisory () https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json - Patch, Third Party Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/353121 - Broken Link () https://gitlab.com/gitlab-org/gitlab/-/issues/353121 - Broken Link
References () https://hackerone.com/reports/1472109 - Permissions Required () https://hackerone.com/reports/1472109 - Permissions Required

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-400 NVD-CWE-Other

Information

Published : 2022-06-06 17:15

Updated : 2024-11-21 06:41


NVD link : CVE-2022-1783

Mitre link : CVE-2022-1783

CVE.ORG link : CVE-2022-1783


JSON object : View

Products Affected

gitlab

  • gitlab