CVE-2021-22262: Medium severity gitlab vulnerability
Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22262?
CVE-2021-22262 is rated as a medium severity vulnerability.
How do I fix CVE-2021-22262?
To fix CVE-2021-22262, upgrade GitLab to version 14.0.9 or later, 14.1.4 or later, or 14.2.2 or later.
Which GitLab versions are affected by CVE-2021-22262?
CVE-2021-22262 affects all GitLab versions starting from 13.12 before 14.0.9, from 14.1 before 14.1.4, and from 14.2 before 14.2.2.
What kind of access issue does CVE-2021-22262 expose?
CVE-2021-22262 allows Jira users without administrative privileges to improperly add and remove Jira Connect names.
Is there a workaround for CVE-2021-22262?
Currently, there is no documented workaround for CVE-2021-22262, and upgrading is the recommended solution.