CVE-2022-1111
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/04/2022
Last modified:
08/08/2023
Description
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
Impact
Base Score 3.x
2.70
Severity 3.x
LOW
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 14.0.0 (including) | 14.7.7 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 14.0.0 (including) | 14.7.7 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 14.8.0 (including) | 14.8.5 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 14.8.0 (including) | 14.8.5 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | 14.9.0 (including) | 14.9.2 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | 14.9.0 (including) | 14.9.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page