Medium severity6.4NVD Advisory· Published Aug 5, 2022· Updated Jun 17, 2026
CVE-2022-2498
CVE-2022-2498
Description
An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 triggered new pipelines with the person who created the tag as the pipeline creator instead of the subscription's author.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.8.0,<15.0.5
- cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*
- (no CPE)range: >=12.8, <15.0.5
- Range: 12.8 <= v < 15.0.5, 15.1 <= v < 15.1.4, 15.2 <= v < 15.2.1
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2498.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/243703nvdBroken LinkVendor Advisory
- hackerone.com/reports/966824nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.