MEDIUM

CVE-2021-22252

Gitlab GitLab 2021-08-23 CVSS v3.1
CVSS
6.5

Description

A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers

Summary dbcve.org

A confusion between tag and branch names in GitLab CE/EE allows a Developer to bypass access controls and access protected CI variables intended only for Maintainers. This is an authorization bypass vulnerability where tag references are improperly evaluated against branch protection rules.

Mitigation

Upgrade GitLab to the patched version as specified in the GitLab security advisory. This is a platform-level fix requiring GitLab version update; no application code changes are involved.

EPSS Score

1.13%
Probability of exploitation in next 30 days
64.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE