HIGH

CVE-2021-22167

Gitlab GitLab 2021-01-15 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

Summary dbcve.org

GitLab versions 12.1 and later contain an authorization bypass vulnerability where incorrect HTTP headers on a specific project page allow unauthenticated attackers temporary read access to private repositories.

Mitigation

Upgrade GitLab to the patched version released to address this vulnerability.

EPSS Score

1.57%
Probability of exploitation in next 30 days
74.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE