#VU63939 Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2022-1783
Published: June 2, 2022
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to group member lock bypass. A remote administrator can add new members to a project within their group, even after their group owner enabled a setting to prevent members from being added to projects within that group.