MEDIUM
CVE-2021-22226
CVSS
6.5
Description
Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9
Summary dbcve.org
GitLab CE/EE versions 13.9 and later contained a broken access control vulnerability where users could bypass protected branch restrictions intended to limit pushes to deploy keys only. Under certain conditions, unauthorized users could push commits to protected branches that were configured to reject user pushes.
Mitigation
Upgrade GitLab to the patched version; review protected branch configurations and audit logs for any unauthorized pushes to affected branches.
EPSS Score
0.92%
Probability of exploitation in next 30 days
58.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.