MEDIUM

CVE-2021-22250

Gitlab GitLab 2021-08-25 CVSS v3.1
CVSS
5.4

Description

Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account

Summary dbcve.org

Improper authorization vulnerability in GitLab CE/EE affecting all versions since 13.3 allowed authenticated users to view and delete impersonation tokens that administrators created for their accounts, enabling unauthorized access to privileged token credentials.

Mitigation

Upgrade GitLab to the patched version released after this vulnerability was identified. Review access logs for any unauthorized token access or deletion attempts.

EPSS Score

0.83%
Probability of exploitation in next 30 days
56th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE