CVE Vulnerabilities

CVE-2021-22192

Published: Mar 24, 2021 | Modified: Mar 26, 2021
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 13.2.0 (including) 13.7.9 (excluding)
Gitlab Gitlab 13.8.0 (including) 13.8.6 (excluding)
Gitlab Gitlab 13.9.0 (including) 13.9.4 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References