CVE-2022-1981: GitLab
Low severity, CVSS 2.7. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specific domains, that allow-list may be bypassed if a Maintainer uses the 'Invite a group' feature to invite a group that has members that don't comply with domain allow-list.
Affected products
- GitLab GitLab: from 12.2.0, before 14.10.5 (fixed in 14.10.5); from 15.0.0, before 15.0.4 (fixed in 15.0.4); version 15.1.0 only
Published 2022-07-01. Last modified 2026-06-17.