MEDIUM

CVE-2021-22201

Gitlab GitLab 2021-04-02 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

Summary dbcve.org

A file read vulnerability in GitLab's import functionality allows specially crafted import files to read arbitrary files on the server via path traversal or file inclusion, affecting all versions since 13.9.

Mitigation

Upgrade GitLab to the patched version or disable/restrict the import functionality as a temporary workaround.

EPSS Score

3.07%
Probability of exploitation in next 30 days
87.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE