3.5

CVE-2022-1111

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 14.0.0 < 14.7.7
Gitlab ≫ GitLab SwEdition enterprise Version >= 14.0.0 < 14.7.7
Gitlab ≫ GitLab SwEdition community Version >= 14.8.0 < 14.8.5
Gitlab ≫ GitLab SwEdition enterprise Version >= 14.8.0 < 14.8.5
Gitlab ≫ GitLab SwEdition community Version >= 14.9.0 < 14.9.2
Gitlab ≫ GitLab SwEdition enterprise Version >= 14.9.0 < 14.9.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.465
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
cve@gitlab.com 2.4 0.9 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1111.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/345236
Broken Link