CVE-2021-22211: Medium severity gitlab vulnerability
Published May 5, 2021
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.
Affected Software
6 affected components
GitLab GitLab>=13.7.0<13.9.7
GitLab GitLab>=13.7.0<13.9.7
GitLab GitLab>=13.10.0<13.10.4
GitLab GitLab>=13.10.0<13.10.4
GitLab GitLab>=13.11.0<13.11.2
GitLab GitLab>=13.11.0<13.11.2
Event History
May 5, 2021
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22211?
CVE-2021-22211 is classified with a medium severity rating due to potential incorrect access handling.
2
How do I fix CVE-2021-22211?
To fix CVE-2021-22211, upgrade GitLab to version 13.9.7, 13.10.4, or 13.11.2 or later.
3
What versions of GitLab are affected by CVE-2021-22211?
CVE-2021-22211 affects all GitLab versions from 13.7.0 up to and including 13.11.2.
4
What functionality is impacted by CVE-2021-22211?
CVE-2021-22211 allows GitLab Dependency Proxy to impersonate a user under certain circumstances.
5
Is user data at risk due to CVE-2021-22211?
Yes, CVE-2021-22211 may lead to incorrect access handling which puts user data at risk.