CVE-2021-22211Incorrect Authorization in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 62.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab13.7.013.9.7+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=13.10, <13.10.4, >=13.11, <13.11.2, >=13.7, <13.9.7+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-79w6-c88v-gfgr: An issue has been discovered in GitLab CE/EE affecting all versions starting from 132022-05-24
OSV
CVE-2021-22211: An issue has been discovered in GitLab CE/EE affecting all versions starting from 132021-05-06

📋Vendor Advisories

2
GitLab
CVE-2021-22211: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impe2021-05-06
Debian
CVE-2021-22211: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro...2021