MEDIUM

CVE-2021-22188

Gitlab GitLab 2021-03-03 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.

Summary dbcve.org

GitLab versions 13.0 and later contained an information disclosure vulnerability where confidential issue titles were exposed through branch logs to unauthorized users. The access control logic for issue titles did not properly enforce confidentiality when displaying information via the branch logs feature, allowing any user with repository access to view sensitive issue titles they should not have access to.

Mitigation

Update GitLab to the patched version (14.x or later per vendor advisories). If immediate patching is not feasible, restrict user access to repositories and review branch log visibility settings to limit exposure of sensitive metadata.

EPSS Score

1.31%
Probability of exploitation in next 30 days
69.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE