CVE Vulnerabilities

CVE-2021-22167

Published: Jan 15, 2021 | Modified: Jan 22, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.1.0 (including) 13.5.6 (excluding)
Gitlab Gitlab 13.6.0 (including) 13.6.4 (excluding)
Gitlab Gitlab 13.7.0 (including) 13.7.2 (excluding)

References