CVE-2022-1111Resource Exposure in Gitlab

Severity
2.7LOWNVD
EPSS
0.2%
top 51.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateApr 13

Description

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab14.0.014.7.7+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=14.0, <14.7.7, >=14.8.0, <14.8.5, >=14.9, <14.9.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

3
GHSA
Cross-site Scripting in Jenkins Credentials Plugin2022-04-13
GHSA
GHSA-2834-55v8-f2v4: A business logic error in Project Import in GitLab CE/EE versions 142022-04-05
OSV
CVE-2022-1111: A business logic error in Project Import in GitLab CE/EE versions 142022-04-04

📋Vendor Advisories

3
Red Hat
credentials: Stored XSS vulnerabilities in jenkins plugin2022-04-12
GitLab
CVE-2022-1111: A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain c2022-04-04
Debian
CVE-2022-1111: gitlab - A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to ...2022