CVE-2022-1783Uncontrolled Resource Consumption in Gitlab

Severity
2.7LOWNVD
EPSS
0.5%
top 35.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6
Latest updateJun 7

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab14.3.014.9.5+2
CVEListV5gitlab/gitlab>=14.10.0, <14.10.4, >=14.3, <14.9.5, >=15.0.0, <15.0.1+2
debiandebian/gitlab
gitlabgitlab/gitlab

Patches

🔴Vulnerability Details

1
GHSA
GHSA-gqc9-9f54-xc45: An issue has been discovered in GitLab CE/EE affecting all versions starting from 142022-06-07

📋Vendor Advisories

2
GitLab
CVE-2022-1783: An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4,2022-06-06
Debian
CVE-2022-1783: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro...2022