CVE-2022-1999

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 06:41

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1999.json - Vendor Advisory () https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1999.json - Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/357963 - Broken Link () https://gitlab.com/gitlab-org/gitlab/-/issues/357963 - Broken Link
CVSS v2 : 4.3
v3 : 5.3
v2 : 4.3
v3 : 3.1

Information

Published : 2022-07-01 17:15

Updated : 2024-11-21 06:41


NVD link : CVE-2022-1999

Mitre link : CVE-2022-1999

CVE.ORG link : CVE-2022-1999


JSON object : View

Products Affected

gitlab

  • gitlab