An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. Membership changes are not reflected in TODO for confidential notes, allowing a former project members to read updates via TODOs.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/365742 | Broken Link Vendor Advisory |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2512.json | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2022-08-05 09:15
Updated : 2022-08-11 08:22
NVD link : CVE-2022-2512
Mitre link : CVE-2022-2512
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
gitlab
- gitlab