CVE-2021-22193Information Exposure via Error Message in Gitlab

Severity
3.5LOWNVD
EPSS
0.3%
top 48.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 24
Latest updateMay 24

Description

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 2.1 | Impact: 1.4

Affected Packages4 packages

NVDgitlab/gitlab7.1.013.6.6+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=13.7, <13.7.6, >=13.8, <13.8.2, >=7.1, <13.6.6+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-2j7r-vr72-m9vf: An issue has been discovered in GitLab affecting all versions starting with 72022-05-24
OSV
CVE-2021-22193: An issue has been discovered in GitLab affecting all versions starting with 72021-03-24

📋Vendor Advisories

2
GitLab
CVE-2021-22193: An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specifi2021-03-24
Debian
CVE-2021-22193: gitlab - An issue has been discovered in GitLab affecting all versions starting with 7.1....2021