First published: Fri Jul 01 2022(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.13.0<14.10.5 | |
GitLab | >=8.13.0<14.10.5 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | =15.1.0 | |
GitLab | =15.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1999 has a severity rating of medium due to the impact of unprivileged users being able to change label descriptions.
To fix CVE-2022-1999, update your GitLab installation to version 14.10.5 or higher, 15.0.4 or higher, or 15.1.1.
CVE-2022-1999 affects GitLab versions from 8.13 to before 14.10.5, 15.0 to before 15.0.4, and version 15.1.0.
Due to CVE-2022-1999, an attacker can exploit the REST API to alter label descriptions, potentially leading to misinformation.
There are no documented workarounds for CVE-2022-1999; the recommended action is to upgrade to a patched version of GitLab.