CVE-2021-22190: Path Traversal
Published Apr 12, 2021
·Updated
A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token
Affected Software
6 affected components
GitLab GitLab>=13.7.0<13.7.8
GitLab GitLab>=13.7.0<13.7.8
GitLab GitLab>=13.8.0<13.8.5
GitLab GitLab>=13.8.0<13.8.5
GitLab GitLab>=13.9.0<13.9.2
GitLab GitLab>=13.9.0<13.9.2
Event History
Apr 12, 2021
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22190?
CVE-2021-22190 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2021-22190?
To fix CVE-2021-22190, upgrade GitLab to version 13.7.9, 13.8.6, or 13.9.3 or later.
3
What systems are affected by CVE-2021-22190?
CVE-2021-22190 affects GitLab Community and Enterprise Editions from versions 13.7.0 to 13.9.2.
4
What kind of vulnerability is CVE-2021-22190?
CVE-2021-22190 is a path traversal vulnerability that can lead to the exposure of a JWT token.
5
How can CVE-2021-22190 be exploited?
CVE-2021-22190 can be exploited by an attacker who sends crafted requests to the GitLab Workhorse that bypasses security restrictions.