HIGH
CVE-2021-22209
CVSS
7.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.
Summary dbcve.org
GitLab CE/EE versions 13.8 and later had improper validation of authorization tokens in the GraphQL API, allowing unauthenticated or improperly authenticated users to execute GraphQL mutations they should not have access to.
Mitigation
Upgrade GitLab to the version containing the patched authorization validation for GraphQL mutations. Verify that all GraphQL endpoints properly validate authorization tokens after the update.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.93%
Probability of exploitation in next 30 days
59.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.