CVE-2021-22244: Medium severity gitlab vulnerability
Published Aug 25, 2021
·Updated
Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data
Affected Software
3 affected components
GitLab GitLab>=13.1.0<13.12.9
GitLab GitLab>=14.0.0<14.0.7
GitLab GitLab>=14.1.0<14.1.2
Event History
Aug 25, 2021
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22244?
CVE-2021-22244 has a high severity rating due to its potential to expose sensitive vulnerability data.
2
How do I fix CVE-2021-22244?
To fix CVE-2021-22244, users should upgrade GitLab EE to version 13.12.10 or later, or versions 14.0.8 or later.
3
What versions of GitLab are affected by CVE-2021-22244?
CVE-2021-22244 affects GitLab EE versions from 13.1.0 to 13.12.9 and 14.0.0 to 14.0.7.
4
Who is impacted by CVE-2021-22244?
Users who can report vulnerabilities in GitLab EE are impacted because they may access unauthorized vulnerability data.
5
Is CVE-2021-22244 present in all GitLab EE versions?
No, CVE-2021-22244 is only present in GitLab EE versions between 13.1.0 and 14.0.7 and in specific versions of 14.1.