HIGH

CVE-2021-22229

Gitlab GitLab 2021-07-06 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab's fork functionality. Under a specific condition, a project member could access data from an internal repository by creating a fork, bypassing intended access controls that should prevent members from accessing internal-only repository content.

Mitigation

Upgrade GitLab to the patched version. Review fork permissions and ensure project membership configurations align with the principle of least privilege for internal repositories.

EPSS Score

1.08%
Probability of exploitation in next 30 days
63.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE