MEDIUM
CVE-2021-22250
CVSS
5.4
Description
Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account
Summary dbcve.org
Improper authorization vulnerability in GitLab CE/EE affecting all versions since 13.3 allowed authenticated users to view and delete impersonation tokens that administrators created for their accounts, enabling unauthorized access to privileged token credentials.
Mitigation
Upgrade GitLab to the patched version released after this vulnerability was identified. Review access logs for any unauthorized token access or deletion attempts.
EPSS Score
0.83%
Probability of exploitation in next 30 days
56th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.