MEDIUM

CVE-2021-22226

Gitlab GitLab 2021-07-06 CVSS v3.1
CVSS
6.5

Description

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

Summary dbcve.org

GitLab CE/EE versions 13.9 and later contained a broken access control vulnerability where users could bypass protected branch restrictions intended to limit pushes to deploy keys only. Under certain conditions, unauthorized users could push commits to protected branches that were configured to reject user pushes.

Mitigation

Upgrade GitLab to the patched version; review protected branch configurations and audit logs for any unauthorized pushes to affected branches.

EPSS Score

0.92%
Probability of exploitation in next 30 days
58.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE