MEDIUM
CVE-2021-22244
CVSS
6.5
Description
Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data
Summary dbcve.org
Improper authorization in GitLab EE's vulnerability report feature allowed users with reporter-level permissions to access vulnerability data they should not have had access to, representing a vertical privilege escalation via authorization bypass.
Mitigation
Upgrade GitLab EE to a patched version that addresses this authorization flaw in the vulnerability report feature.
EPSS Score
1.01%
Probability of exploitation in next 30 days
61.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.