CVE-2021-22231: Medium severity gitlab vulnerability
Published Jul 7, 2021
·Updated
A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.
Affected Software
6 affected components
GitLab GitLab>=8.0.0<13.11.6
GitLab GitLab>=13.12.0<13.12.6
GitLab GitLab>=14.0.0<14.0.2
GitLab GitLab>=8.0.0<13.11.6
GitLab GitLab>=13.12.0<13.12.6
GitLab GitLab>=14.0.0<14.0.2
Event History
Jul 7, 2021
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22231?
CVE-2021-22231 has a high severity due to its potential to cause denial of service on user profile pages.
2
How do I fix CVE-2021-22231?
To fix CVE-2021-22231, upgrade your GitLab instance to the latest version that addresses this vulnerability.
3
What versions of GitLab are affected by CVE-2021-22231?
CVE-2021-22231 affects GitLab CE/EE versions from 8.0.0 up to and including 14.0.2.
4
Can CVE-2021-22231 be exploited remotely?
Yes, CVE-2021-22231 can be exploited remotely by an attacker using a specially crafted username.
5
What impact does CVE-2021-22231 have on GitLab users?
The impact of CVE-2021-22231 can prevent users from accessing their profile pages, resulting in service disruption.