First published: Tue Jul 06 2021(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.8<13.11.6 | |
GitLab | >=13.12.0<13.12.6 | |
GitLab | >=14.0.0<14.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22229 is classified as a medium severity vulnerability.
To fix CVE-2021-22229, upgrade your GitLab instance to a version greater than 13.11.6, 13.12.6 or 14.0.2.
CVE-2021-22229 affects all GitLab versions starting from 12.8 up to version 14.0.2.
CVE-2021-22229 is a data exposure vulnerability that allows access to internal repository data.
Yes, CVE-2021-22229 can significantly impact your GitLab project security by potentially exposing sensitive internal repository data.