CVE-2021-22229: High severity gitlab vulnerability
Published Jul 6, 2021
·Updated
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.
Affected Software
3 affected components
GitLab GitLab>=12.8<13.11.6
GitLab GitLab>=13.12.0<13.12.6
GitLab GitLab>=14.0.0<14.0.2
Event History
Jul 6, 2021
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22229?
CVE-2021-22229 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-22229?
To fix CVE-2021-22229, upgrade your GitLab instance to a version greater than 13.11.6, 13.12.6 or 14.0.2.
3
Which versions of GitLab are affected by CVE-2021-22229?
CVE-2021-22229 affects all GitLab versions starting from 12.8 up to version 14.0.2.
4
What type of vulnerability is CVE-2021-22229?
CVE-2021-22229 is a data exposure vulnerability that allows access to internal repository data.
5
Can CVE-2021-22229 impact my GitLab project security?
Yes, CVE-2021-22229 can significantly impact your GitLab project security by potentially exposing sensitive internal repository data.