CVE-2022-1981: Low severity gitlab vulnerability
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1981?
CVE-2022-1981 has been rated as critical due to the potential for bypassing access restrictions in GitLab.
How do I fix CVE-2022-1981?
To fix CVE-2022-1981, upgrade GitLab to version 14.10.5 or higher, 15.0.4 or higher, or 15.1.1.
What versions of GitLab are affected by CVE-2022-1981?
CVE-2022-1981 affects GitLab EE versions from 12.2 up to but not including 14.10.5, 15.0 up to but not including 15.0.4, and 15.1 up to but not including 15.1.1.
What is the nature of the vulnerability CVE-2022-1981?
CVE-2022-1981 allows a Maintainer to bypass access restrictions based on user domains in GitLab.
Can CVE-2022-1981 impact my GitLab instance?
Yes, if your GitLab instance is running a vulnerable version and has domain restrictions enabled, it can be impacted by CVE-2022-1981.