MEDIUM
CVE-2021-22210
CVSS
5.3
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.
Summary dbcve.org
In GitLab CE/EE versions 13.2 and later, the repository branches API endpoint ignores a query parameter (likely a limit/filter parameter), causing it to return significantly more results than intended. This leads to unintended information disclosure through API responses.
Mitigation
Upgrade GitLab to the patched version (14.x and later contain the fix). No client-side configuration can remediate this server-side code defect.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
1.15%
Probability of exploitation in next 30 days
65.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.