CVE-2021-22189: High severity gitlab vulnerability
Published Mar 4, 2021
·Updated
Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.
Affected Software
6 affected components
GitLab GitLab<13.6.7
GitLab GitLab<13.6.7
GitLab GitLab>=13.7.0<13.7.7
GitLab GitLab>=13.7.0<13.7.7
GitLab GitLab>=13.8.0<13.8.4
GitLab GitLab>=13.8.0<13.8.4
Event History
Mar 4, 2021
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22189?
CVE-2021-22189 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2021-22189?
To address CVE-2021-22189, upgrade GitLab to a version later than 13.8.4.
3
Which versions of GitLab are affected by CVE-2021-22189?
CVE-2021-22189 affects GitLab versions between 13.7.0 and 13.8.4, including versions 13.6.7 and below.
4
What issues can arise from CVE-2021-22189?
CVE-2021-22189 can lead to authentication issues due to improper validation of certificates for the Fortinet OTP.
5
Is CVE-2021-22189 fixed in the latest GitLab release?
Yes, CVE-2021-22189 is fixed in GitLab version 13.8.5 and later.