MEDIUM

CVE-2021-22244

Gitlab GitLab 2021-08-25 CVSS v3.1
CVSS
6.5

Description

Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data

Summary dbcve.org

Improper authorization in GitLab EE's vulnerability report feature allowed users with reporter-level permissions to access vulnerability data they should not have had access to, representing a vertical privilege escalation via authorization bypass.

Mitigation

Upgrade GitLab EE to a patched version that addresses this authorization flaw in the vulnerability report feature.

EPSS Score

1.01%
Probability of exploitation in next 30 days
61.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE