HIGH
CVE-2021-22200
CVSS
7.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.
Summary dbcve.org
Broken access control vulnerability in GitLab CE/EE where an anonymous user could access data from an internal repository by exploiting the fork relationship with a public project, bypassing intended permission boundaries between internal and public project visibility levels.
Mitigation
Upgrade GitLab to the patched version addressing CVE-2021-22200. Review internal repository visibility settings and fork relationships until the upgrade is completed.
EPSS Score
1%
Probability of exploitation in next 30 days
61.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.