#VU65893 Improper access control in GitLab Enterprise Edition - CVE-2022-2459
Published: July 29, 2022
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote administrator to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the email invited members can join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled