CVE-2022-2539: Medium severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.6 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1, allowed a project member to filter issues by contact and organization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2539?
CVE-2022-2539 is classified as a medium severity vulnerability affecting GitLab offerings.
How do I fix CVE-2022-2539?
To fix CVE-2022-2539, upgrade your GitLab installation to version 15.0.5, 15.1.4, or 15.2.1 or later.
Which versions of GitLab are affected by CVE-2022-2539?
CVE-2022-2539 affects GitLab CE/EE versions from 14.6 to versions prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1.
What type of exposure does CVE-2022-2539 offer?
CVE-2022-2539 allows a project member to filter issues by contact and organization, potentially leading to information disclosure.
Is CVE-2022-2539 present in both GitLab CE and EE?
Yes, CVE-2022-2539 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) versions.