MEDIUM

CVE-2021-22210

Gitlab GitLab 2021-05-06 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

Summary dbcve.org

In GitLab CE/EE versions 13.2 and later, the repository branches API endpoint ignores a query parameter (likely a limit/filter parameter), causing it to return significantly more results than intended. This leads to unintended information disclosure through API responses.

Mitigation

Upgrade GitLab to the patched version (14.x and later contain the fix). No client-side configuration can remediate this server-side code defect.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

1.15%
Probability of exploitation in next 30 days
65.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE