« Back to list

CVE-2022-1783

Status: ModifiedLow (2.7)—

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2022-1783",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@gitlab.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@gitlab.com",
      "affectedData": [
        {
          "vendor": "GitLab",
          "product": "GitLab",
          "versions": [
            {
              "status": "affected",
              "version": ">=15.0.0, <15.0.1"
            },
            {
              "status": "affected",
              "version": ">=14.10.0, <14.10.4"
            },
            {
              "status": "affected",
              "version": ">=14.3, <14.9.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-06-06T17:15:10.543",
  "references": [
    {
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/353121",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://hackerone.com/reports/1472109",
      "tags": [
        "Permissions Required"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1783.json",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/353121",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hackerone.com/reports/1472109",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. It may be possible for malicious group maintainers to add new members to a project within their group, through the REST API, even after their group owner enabled a setting to prevent members from being added to projects within that group."
    },
    {
      "lang": "es",
      "value": "Se ha detectado un problema en GitLab CE/EE afectando a todas las versiones a partir de 14.3 anteriores a 14.9.5, todas las versiones a partir de 14.10 anteriores a 14.10.4, todas las versiones a partir de 15.0 anteriores a 15.0.1. Es posible a mantenedores de grupos maliciosos añadir nuevos miembros a un proyecto dentro de su grupo, mediante la API REST, incluso después de que el propietario de su grupo haya habilitado una configuración para evitar que se añadan miembros a los proyectos dentro de ese grupo"
    }
  ],
  "lastModified": "2026-06-17T04:23:06.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51B378B5-906F-4CE2-9C91-53F9F9F5DAD3",
              "versionEndExcluding": "14.9.5",
              "versionStartIncluding": "14.3.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B8B95B6-6915-4DF1-ADBE-707119C9968F",
              "versionEndExcluding": "14.9.5",
              "versionStartIncluding": "14.3.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E69F4A1-5B3A-4FF5-95EC-62DCEB7DCE5F",
              "versionEndExcluding": "14.10.4",
              "versionStartIncluding": "14.10.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E6B5E02-4670-4E74-A3EA-DF81659861E1",
              "versionEndExcluding": "14.10.4",
              "versionStartIncluding": "14.10.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00FDE831-EC28-4124-AC9F-A1C089D5BBFA"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8953D9B-56DF-4AA2-BFDC-B28CF4F31CB5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@gitlab.com"
}