First published: Thu May 06 2021(Updated: )
An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.5.0<13.9.7 | |
GitLab | >=13.5.0<13.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22208 has been classified as a medium severity vulnerability due to its potential to affect the integrity of issue timestamps.
To fix CVE-2021-22208, upgrade GitLab to version 13.9.8 or later.
CVE-2021-22208 affects GitLab versions from 13.5.0 up to 13.9.7.
CVE-2021-22208 could allow unauthorized users to modify timestamps for issue creation or updates.
There is no official workaround for CVE-2021-22208; upgrading to a patched version is strongly recommended.