VulnerabilityModified
CVE-2022-1111
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the…
LOW 2.7EPSS 0.63%
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
- CVSS 3.1
- 2.7 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1111.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/345236Broken Link
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1111.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/345236Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.