Low severity2.7NVD Advisory· Published Jul 1, 2022· Updated Jun 17, 2026
CVE-2022-1981
CVE-2022-1981
Description
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.2.0,<14.10.5
- cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*
- (no CPE)range: >=12.2, <14.10.5
- Range: from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1981.jsonnvdVendor Advisory
- hackerone.com/reports/1501733nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/354791nvdBroken Link
News mentions
0No linked articles in our index yet.