HIGH
CVE-2021-22167
CVSS
7.5
Description
An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository
Summary dbcve.org
GitLab versions 12.1 and later contain an authorization bypass vulnerability where incorrect HTTP headers on a specific project page allow unauthenticated attackers temporary read access to private repositories.
Mitigation
Upgrade GitLab to the patched version released to address this vulnerability.
EPSS Score
1.57%
Probability of exploitation in next 30 days
74.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.