HIGH
CVE-2021-22229
CVSS
7.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.
Summary dbcve.org
This is an authorization bypass vulnerability in GitLab's fork functionality. Under a specific condition, a project member could access data from an internal repository by creating a fork, bypassing intended access controls that should prevent members from accessing internal-only repository content.
Mitigation
Upgrade GitLab to the patched version. Review fork permissions and ensure project membership configurations align with the principle of least privilege for internal repositories.
EPSS Score
1.08%
Probability of exploitation in next 30 days
63.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.