VulnerabilityModified
CVE-2021-22188
Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.
MEDIUM 5.3EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an unauthorised user via branch logs.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22188.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/227040Broken Link
- https://hackerone.com/reports/916340Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22188.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/227040Broken Link
- https://hackerone.com/reports/916340Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.