Input validation error in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2022-2307

 

Input validation error in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2022-2307

Published: July 29, 2022


Vulnerability identifier: #VU65889
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2307
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a lack of cascading deletes. A remote administrator can retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition

How to mitigate CVE-2022-2307

Install updates from vendor's website.

GitLab Enterprise Edition - addressed in versions 15.0.5, 15.1.4, 15.2.1
Gitlab Community Edition - addressed in versions 15.0.5, 15.1.4, 15.2.1

External References

Related Security Bulletins