MEDIUM
CVE-2021-22253
CVSS
5.4
Description
Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed
Summary dbcve.org
Improper authorization vulnerability in GitLab EE allows users who previously had deployment access to protected environments to still trigger deployments after their access has been removed. This authorization bypass affects all versions since 13.4 and occurs under specific conditions.
Mitigation
Upgrade GitLab EE to the patched version provided in the security release. There are no known workarounds; immediate patching is the recommended remediation.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.82%
Probability of exploitation in next 30 days
55.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.