CVE-2021-22248Incorrect Authorization in Gitlab

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 55.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 24

Description

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab13.12.013.12.9+2
CVEListV5gitlab/gitlab>=13.12, <13.12.9, >=14.0, <14.0.7, >=14.1, <14.1.2+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-w37f-8cwf-64g5: Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 132022-05-24
OSV
CVE-2021-22248: Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 132021-08-23

📋Vendor Advisories

2
GitLab
CVE-2021-22248: Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline infor2021-08-23
Debian
CVE-2021-22248: gitlab - Improper authorization on the pipelines page in GitLab CE/EE affecting all versi...2021