CVE-2022-2307

Name
CVE-2022-2307
Description
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the Group is deleted, though the APIs usable by that token are limited.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2307.json
MISC https://gitlab.com/gitlab-org/gitlab/-/issues/360025

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* gitlab >= 13.0.0 < 15.0.5
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* gitlab >= 15.1.0 < 15.1.4
cpe:2.3:a:gitlab:gitlab:15.2:*:*:*:enterprise:*:*:* gitlab == None == 15.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status