First published: Mon Aug 23 2021(Updated: )
Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.12.0<13.12.9 | |
GitLab | >=13.12.0<13.12.9 | |
GitLab | >=14.0.0<14.0.7 | |
GitLab | >=14.0.0<14.0.7 | |
GitLab | >=14.1.0<14.1.2 | |
GitLab | >=14.1.0<14.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22248 has a medium severity rating due to improper authorization allowing unauthorized access to pipeline information.
To fix CVE-2021-22248, upgrade your GitLab instance to version 13.12.9 or later, or versions 14.0.7 or later.
CVE-2021-22248 affects all GitLab CE and EE versions from 13.12 to 14.1.2, allowing unauthorized users access to pipeline details in public projects.
The impact of CVE-2021-22248 is that it enables unauthorized users to view sensitive pipeline information in restricted public projects.
Yes, CVE-2021-22248 is fixed in subsequent GitLab releases, ensuring that unauthorized access is prevented.