CVE-2021-22256: Medium severity gitlab vulnerability
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22256?
CVE-2021-22256 has been classified with a medium severity due to improper authorization allowing guest users to create issues.
How do I fix CVE-2021-22256?
To remediate CVE-2021-22256, you should upgrade GitLab to version 13.12.10 or 14.0.8 and later versions that include the security fix.
Who is affected by CVE-2021-22256?
CVE-2021-22256 affects all GitLab CE and EE versions from 12.6.0 up to but not including specific patched versions.
What types of users are impacted by CVE-2021-22256?
Guest users are specifically impacted by CVE-2021-22256, being able to create and track Sentry error issues.
Is CVE-2021-22256 a persistent issue in GitLab?
CVE-2021-22256 is not persistent as it can be resolved by upgrading to the recommended versions without the vulnerability.