Low severity3.1NVD Advisory· Published Jul 1, 2022· Updated Jun 17, 2026
CVE-2022-1999
CVE-2022-1999
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. Under certain conditions, using the REST API an unprivileged user was able to change labels description.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.13.0,<14.10.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.13.0,<14.10.5
- cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:15.1.0:*:*:*:enterprise:*:*:*
- (no CPE)range: from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1
- (no CPE)range: >=8.13, <14.10.5
- Range: from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1999.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/357963nvdBroken Link
News mentions
0No linked articles in our index yet.