CVE Vulnerabilities

CVE-2021-22248

Published: Aug 23, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab13.12.0 (including)13.12.9 (excluding)
GitlabGitlab14.0.0 (including)14.0.7 (excluding)
GitlabGitlab14.1.0 (including)14.1.2 (excluding)
GitlabUbuntuesm-apps/xenial*
GitlabUbuntuxenial*

References