First published: Wed Jul 07 2021(Updated: )
A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.0.0<13.11.6 | |
GitLab | >=13.12.0<13.12.6 | |
GitLab | >=14.0.0<14.0.2 | |
GitLab | >=8.0.0<13.11.6 | |
GitLab | >=13.12.0<13.12.6 | |
GitLab | >=14.0.0<14.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22231 has a high severity due to its potential to cause denial of service on user profile pages.
To fix CVE-2021-22231, upgrade your GitLab instance to the latest version that addresses this vulnerability.
CVE-2021-22231 affects GitLab CE/EE versions from 8.0.0 up to and including 14.0.2.
Yes, CVE-2021-22231 can be exploited remotely by an attacker using a specially crafted username.
The impact of CVE-2021-22231 can prevent users from accessing their profile pages, resulting in service disruption.