Medium severity5.7NVD Advisory· Published Mar 9, 2023· Updated Jun 17, 2026
CVE-2022-4331
CVE-2022-4331
Description
An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.1,<15.7.8
- (no CPE)range: starting from 15.1 before 15.7.8, starting from 15.8 before 15.8.4, starting from 15.9 before 15.9.2
- (no CPE)range: >=15.1, <15.7.8
- Range: starting from 15.1 before 15.7.8, starting from 15.8 before 15.8.4, starting from 15.9 before 15.9.2
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4331.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/385050nvdBroken Link
- hackerone.com/reports/1791518nvdPermissions Required
News mentions
0No linked articles in our index yet.