CVE-2021-22188: Medium severity gitlab vulnerability
Published Mar 3, 2021
·Updated
An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.
Affected Software
6 affected components
GitLab GitLab>=13.0.0<13.6.7
GitLab GitLab>=13.0.0<13.6.7
GitLab GitLab>=13.7.0<13.7.7
GitLab GitLab>=13.7.0<13.7.7
GitLab GitLab>=13.8.0<13.8.4
GitLab GitLab>=13.8.0<13.8.4
Event History
Mar 3, 2021
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-22188?
CVE-2021-22188 is an issue in GitLab where confidential issue titles were readable by an unauthorized user via branch logs.
2
Which versions of GitLab are affected by CVE-2021-22188?
All versions of GitLab starting from 13.0 up to 13.6.7 are affected by CVE-2021-22188.
3
How severe is CVE-2021-22188?
CVE-2021-22188 has a severity rating of medium with a CVSS score of 5.3.
4
How can I fix CVE-2021-22188?
To fix CVE-2021-22188, it is recommended to upgrade GitLab to version 13.6.8 or later.
5
Where can I find more information about CVE-2021-22188?
You can find more information about CVE-2021-22188 on the GitLab CVE page and the associated GitLab and HackerOne links.