CVE-2022-0740
4.3
MEDIUM
CVSS 3.1
EPSS 0.08%
Description
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.
How to fix CVE-2022-0740
To remediate CVE-2022-0740, upgrade the affected package to a fixed version below.
- Bitnami/gitlab—upgrade to 14.7.7 or later
Is CVE-2022-0740 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 7.8.0, < 14.7.7, >= 14.8.0, < 14.8.5, >= 14.9.0, < 14.9.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |