MEDIUM

CVE-2021-22253

Gitlab GitLab 2021-08-23 CVSS v3.1
CVSS
5.4

Description

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

Summary dbcve.org

Improper authorization vulnerability in GitLab EE allows users who previously had deployment access to protected environments to still trigger deployments after their access has been removed. This authorization bypass affects all versions since 13.4 and occurs under specific conditions.

Mitigation

Upgrade GitLab EE to the patched version provided in the security release. There are no known workarounds; immediate patching is the recommended remediation.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.82%
Probability of exploitation in next 30 days
55.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE