VYPR
Low severity2.4NVD Advisory· Published Apr 4, 2022· Updated Jun 17, 2026

CVE-2022-1111

CVE-2022-1111

Description

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=14.0.0,<14.7.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=14.0.0,<14.7.7
    • (no CPE)range: >=14.9, <14.9.2
  • Range: <14.9.2, <14.8.5, <14.7.7
  • osv-coords
    Range: >= 14.0.0, < 14.7.7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.