Low severity3.5NVD Advisory· Published Aug 5, 2022· Updated Jun 17, 2026
CVE-2022-2499
CVE-2022-2499
Description
An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that may be exploited by an attacker to leak Jira issues.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.10.0,<15.0.5
- cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:*
- (no CPE)range: starting from 13.10 before 15.0.5, starting from 15.1 before 15.1.4, starting from 15.2 before 15.2.1
- (no CPE)range: >=13.10, <15.0.5
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2499.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/360800nvdBroken LinkVendor Advisory
- hackerone.com/reports/1538068nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.