MEDIUM
CVE-2021-22201
CVSS
6.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.
Summary dbcve.org
A file read vulnerability in GitLab's import functionality allows specially crafted import files to read arbitrary files on the server via path traversal or file inclusion, affecting all versions since 13.9.
Mitigation
Upgrade GitLab to the patched version or disable/restrict the import functionality as a temporary workaround.
EPSS Score
3.07%
Probability of exploitation in next 30 days
87.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.