First published: Thu Sep 09 2021(Updated: )
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=14.0.0<14.0.7 | |
GitLab | >=14.0.0<14.0.7 | |
GitLab | >=14.1.0<14.1.2 | |
GitLab | >=14.1.0<14.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-22239 is classified as a high-risk vulnerability due to the potential for unauthorized access.
To fix CVE-2021-22239, upgrade to GitLab version 14.0.8 or later for both Community and Enterprise editions.
CVE-2021-22239 allows unauthorized users to insert malicious metadata when creating new issues, which could lead to further exploitation.
CVE-2021-22239 affects GitLab versions 14.0.0 through 14.1.2 for both Community and Enterprise editions.
CVE-2021-22239 is not present in versions prior to 14.0.0 of GitLab.