CVE Vulnerabilities

CVE-2021-22231

Published: Jul 07, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A denial of service in users profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 8.0.0 (including) 13.11.6 (excluding)
Gitlab Gitlab 13.12.0 (including) 13.12.6 (excluding)
Gitlab Gitlab 14.0.0 (including) 14.0.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References