VulnerabilityModified
CVE-2021-22176
Improper access control allows demoted project members to access details on authored merge requests
MEDIUM 4.3EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22176.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/243491Vendor Advisory
- https://hackerone.com/reports/962604Issue Tracking, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22176.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/243491Vendor Advisory
- https://hackerone.com/reports/962604Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.