Low severity3.1NVD Advisory· Published Apr 4, 2022· Updated Jun 17, 2026
CVE-2022-0740
CVE-2022-0740
Description
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=7.8.0,<14.7.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=7.8.0,<14.7.7
- (no CPE)range: >=7.8, <14.7.7
- Range: from 7.8.0 before 14.7.7, from 14.8 before 14.8.5, from 14.9 before 14.9.2
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0740.jsonnvdVendor Advisory
- hackerone.com/reports/1411216nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/349359nvdBroken Link
News mentions
0No linked articles in our index yet.