First published: Thu Mar 04 2021(Updated: )
Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <13.6.7 | |
GitLab | <13.6.7 | |
GitLab | >=13.7.0<13.7.7 | |
GitLab | >=13.7.0<13.7.7 | |
GitLab | >=13.8.0<13.8.4 | |
GitLab | >=13.8.0<13.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22189 has been classified as a medium severity vulnerability.
To address CVE-2021-22189, upgrade GitLab to a version later than 13.8.4.
CVE-2021-22189 affects GitLab versions between 13.7.0 and 13.8.4, including versions 13.6.7 and below.
CVE-2021-22189 can lead to authentication issues due to improper validation of certificates for the Fortinet OTP.
Yes, CVE-2021-22189 is fixed in GitLab version 13.8.5 and later.