First published: Mon Jun 06 2022(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for a subgroup member to access the members list of their parent group.
Credit: cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=10.8.0<14.9.5 | |
GitLab | >=10.8.0<14.9.5 | |
GitLab | >=14.10.0<14.10.4 | |
GitLab | >=14.10.0<14.10.4 | |
GitLab | =15.0.0 | |
GitLab | =15.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1821 is considered a moderate severity vulnerability that allows subgroup members to potentially access the member list of their parent group.
To fix CVE-2022-1821, upgrade GitLab to version 14.9.5, 14.10.4, or any version above 15.0.1.
CVE-2022-1821 affects GitLab CE/EE versions starting from 10.8 up to 14.9.5, 14.10 from 14.10.0 to 14.10.4, and version 15.0.0.
Yes, subgroup members may be able to exploit CVE-2022-1821 to gain unauthorized access to the members list of their parent group.
No, CVE-2022-1821 is not present in GitLab's versions released after 14.9.5, 14.10.4, and 15.0.1.