CVE-2021-22237: Medium severity gitlab vulnerability
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22237?
CVE-2021-22237 is considered a high-severity vulnerability that allows unauthorized Git actions under specific conditions.
How do I fix CVE-2021-22237?
To remediate CVE-2021-22237, upgrade to GitLab versions 13.12.9, 14.0.7, or 14.1.2 or later.
Who is affected by CVE-2021-22237?
CVE-2021-22237 affects GitLab Community and Enterprise editions prior to the specified patched versions.
What can an attacker do with CVE-2021-22237?
An attacker can perform Git actions using an impersonation token even if impersonation is disabled, potentially leading to unauthorized access.
What versions of GitLab are vulnerable to CVE-2021-22237?
GitLab CE/EE versions before 13.12.9, 14.0.7, and 14.1.2 are vulnerable to CVE-2021-22237.