First published: Fri Jul 01 2022(Updated: )
An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows project memebers with reporter role to manage issues in project's error tracking feature.
Credit: cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=14.8.0<14.10.5 | |
GitLab | >=14.8.0<14.10.5 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | >=15.0.0<15.0.4 | |
GitLab | =15.1.0 | |
GitLab | =15.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2244 is classified as a medium severity vulnerability due to improper authorization risks.
To fix CVE-2022-2244, update GitLab to versions 14.10.5, 15.0.4, or 15.1.1 or later.
CVE-2022-2244 affects all versions of GitLab EE/CE from 14.8 to prior versions of 14.10.5, 15.0 to prior versions of 15.0.4, and 15.1 up to 15.1.0.
CVE-2022-2244 is an improper authorization vulnerability.
CVE-2022-2244 allows project members with the reporter role to manage issues in the project's error tracking feature.