CVE-2021-22244Incorrect Authorization in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 65.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 24

Description

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

NVDgitlab/gitlab13.1.013.12.9+2
CVEListV5gitlab/gitlab>=13.1, <13.12.9, >=14.0, <14.0.7, >=14.1, <14.1.2+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-jrrv-jm33-8jrv: Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 132022-05-24
OSV
CVE-2021-22244: Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 132021-08-25

📋Vendor Advisories

2
GitLab
CVE-2021-22244: Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability d2021-08-25
Debian
CVE-2021-22244: gitlab - Improper authorization in the vulnerability report feature in GitLab EE affectin...2021