CVE-2021-22197: Medium severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when an authenticated user with specific rights access a MR having source and target branch pointing to each other
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22197?
CVE-2021-22197 is classified as a critical vulnerability due to the potential denial of service through an infinite loop.
How does CVE-2021-22197 affect GitLab users?
CVE-2021-22197 affects authenticated users with specific rights when accessing merge requests that have source and target branches pointing to each other.
Which versions of GitLab are impacted by CVE-2021-22197?
CVE-2021-22197 affects all GitLab versions starting from 10.6 up to and including 13.10.1.
How do I fix CVE-2021-22197?
To fix CVE-2021-22197, users should upgrade to a patched version of GitLab, specifically 13.10.1 or later.
What should I do if I cannot upgrade GitLab to mitigate CVE-2021-22197?
If upgrading is not possible, it is recommended to restrict access rights for users who can access merge requests until you can apply the necessary updates.