CVE-2022-2326: High severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2326?
CVE-2022-2326 is classified as a high severity vulnerability.
How do I fix CVE-2022-2326?
To fix CVE-2022-2326, upgrade GitLab to version 15.0.5 or 15.1.4 and above.
What software is affected by CVE-2022-2326?
CVE-2022-2326 affects all versions of GitLab Community and Enterprise editions prior to 15.0.5, versions from 15.1.0 to 15.1.4, and versions from 15.2.0 to 15.2.1.
What kind of access can be gained through CVE-2022-2326?
CVE-2022-2326 may allow unauthorized access to private projects using another user's email address.
Is there a workaround for CVE-2022-2326?
There are no recommended workarounds for CVE-2022-2326; patching is the only solution.