First published: Wed May 05 2021(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.7.0<13.9.7 | |
GitLab | >=13.7.0<13.9.7 | |
GitLab | >=13.10.0<13.10.4 | |
GitLab | >=13.10.0<13.10.4 | |
GitLab | >=13.11.0<13.11.2 | |
GitLab | >=13.11.0<13.11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22211 is classified with a medium severity rating due to potential incorrect access handling.
To fix CVE-2021-22211, upgrade GitLab to version 13.9.7, 13.10.4, or 13.11.2 or later.
CVE-2021-22211 affects all GitLab versions from 13.7.0 up to and including 13.11.2.
CVE-2021-22211 allows GitLab Dependency Proxy to impersonate a user under certain circumstances.
Yes, CVE-2021-22211 may lead to incorrect access handling which puts user data at risk.