CVE Vulnerabilities

CVE-2021-22252

Published: Aug 23, 2021 | Modified: Jul 12, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to Maintainers

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 13.7.0 (including) 13.12.9 (excluding)
Gitlab Gitlab 14.0.0 (including) 14.0.7 (excluding)
Gitlab Gitlab 14.1.0 (including) 14.1.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References