CVE-2022-1783

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*

History

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-400 NVD-CWE-Other

13 Jun 2022, 17:59

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 2.7
CWE CWE-400
First Time Gitlab
Gitlab gitlab
References (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json - (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json - Patch, Third Party Advisory
References (MISC) https://hackerone.com/reports/1472109 - (MISC) https://hackerone.com/reports/1472109 - Permissions Required
References (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/353121 - (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/353121 - Broken Link

06 Jun 2022, 17:39

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-06 17:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-1783

Mitre link : CVE-2022-1783

CVE.ORG link : CVE-2022-1783


JSON object : View

Products Affected

gitlab

  • gitlab