First published: Fri Apr 02 2021(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.
Credit: cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.8.0<13.8.7 | |
GitLab | >=13.8.0<13.8.7 | |
GitLab | >=13.9.0<13.9.5 | |
GitLab | >=13.9.0<13.9.5 | |
GitLab | >=13.10.0<13.10.1 | |
GitLab | >=13.10.0<13.10.1 | |
GitLab | >=13.8.0 | |
GitLab | >=13.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22198 is classified as a medium severity vulnerability.
To fix CVE-2021-22198, upgrade your GitLab installation to version 13.8.7 or later, or 13.9.5 or later, or 13.10.1 or later.
CVE-2021-22198 affects all authenticated users of GitLab CE/EE versions 13.8 and above.
CVE-2021-22198 enables authenticated users to delete incident metric images from public projects.
CVE-2021-22198 was discovered in 2021, affecting multiple versions of GitLab.