CVE Vulnerabilities

CVE-2021-22203

Published: Apr 02, 2021 | Modified: Jul 22, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7.9 before 13.8.7, all versions starting from 13.9 before 13.9.5, and all versions starting from 13.10 before 13.10.1. A specially crafted Wiki page allowed attackers to read arbitrary files on the server.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 13.7.9 (including) 13.8.7 (excluding)
Gitlab Gitlab 13.9.0 (including) 13.9.5 (excluding)
Gitlab Gitlab 13.10.0 (including) 13.10.0 (including)

References