CVE-2021-22198: Medium severity gitlab vulnerability
Published Apr 2, 2021
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects.
Affected Software
8 affected components
GitLab GitLab>=13.8.0
GitLab GitLab>=13.8.0
GitLab GitLab>=13.8.0<13.8.7
GitLab GitLab>=13.8.0<13.8.7
GitLab GitLab>=13.9.0<13.9.5
GitLab GitLab>=13.9.0<13.9.5
GitLab GitLab>=13.10.0<13.10.1
GitLab GitLab>=13.10.0<13.10.1
Event History
Apr 2, 2021
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22198?
CVE-2021-22198 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-22198?
To fix CVE-2021-22198, upgrade your GitLab installation to version 13.8.7 or later, or 13.9.5 or later, or 13.10.1 or later.
3
Who is affected by CVE-2021-22198?
CVE-2021-22198 affects all authenticated users of GitLab CE/EE versions 13.8 and above.
4
What type of attack does CVE-2021-22198 enable?
CVE-2021-22198 enables authenticated users to delete incident metric images from public projects.
5
When was CVE-2021-22198 discovered?
CVE-2021-22198 was discovered in 2021, affecting multiple versions of GitLab.