CVE-2022-1111: Low severity gitlab vulnerability
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1111?
The severity of CVE-2022-1111 is low.
How does CVE-2022-1111 affect GitLab CE/EE versions?
CVE-2022-1111 affects GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7.
What is the business logic error in CVE-2022-1111?
The business logic error in CVE-2022-1111 occurs in the Project Import feature of GitLab CE/EE.
What is the impact of CVE-2022-1111?
Under certain conditions, imported projects in GitLab CE/EE may show an incorrect user in the 'Access Granted' column in the project membership pages.
How can I fix CVE-2022-1111?
To fix CVE-2022-1111, it is recommended to upgrade to GitLab CE/EE versions 14.9.2, 14.8.5, or 14.7.7 depending on the affected version.