Improper access control in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2022-1783
Published: June 2, 2022
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to group member lock bypass. A remote administrator can add new members to a project within their group, even after their group owner enabled a setting to prevent members from being added to projects within that group.
Affected software
Gitlab Community Edition
How to mitigate CVE-2022-1783
Gitlab Community Edition - addressed in versions 14.9.5, 14.10.4, 15.0.1