MEDIUM
CVE-2021-22252
CVSS
6.5
Description
A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers
Summary dbcve.org
A confusion between tag and branch names in GitLab CE/EE allows a Developer to bypass access controls and access protected CI variables intended only for Maintainers. This is an authorization bypass vulnerability where tag references are improperly evaluated against branch protection rules.
Mitigation
Upgrade GitLab to the patched version as specified in the GitLab security advisory. This is a platform-level fix requiring GitLab version update; no application code changes are involved.
EPSS Score
1.13%
Probability of exploitation in next 30 days
64.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.