HIGH

CVE-2021-22200

Gitlab GitLab 2021-04-02 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.

Summary dbcve.org

Broken access control vulnerability in GitLab CE/EE where an anonymous user could access data from an internal repository by exploiting the fork relationship with a public project, bypassing intended permission boundaries between internal and public project visibility levels.

Mitigation

Upgrade GitLab to the patched version addressing CVE-2021-22200. Review internal repository visibility settings and fork relationships until the upgrade is completed.

EPSS Score

1%
Probability of exploitation in next 30 days
61.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE