VYPR
Low severity3.1NVD Advisory· Published Apr 4, 2022· Updated Jun 17, 2026

CVE-2022-0740

CVE-2022-0740

Description

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=7.8.0,<14.7.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=7.8.0,<14.7.7
    • (no CPE)range: >=7.8, <14.7.7
  • Range: from 7.8.0 before 14.7.7, from 14.8 before 14.8.5, from 14.9 before 14.9.2
  • osv-coords
    Range: >= 7.8.0, < 14.7.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.