VulnerabilityModified
CVE-2021-22208
Improper permission check could allow the change of timestamp for issue creation or update.
MEDIUM 4.3EPSS 0.76%
Does this matter?
Lower severity and a low EPSS score (0.76%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check could allow the change of timestamp for issue creation or update.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22208.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/301212Broken Link
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22208.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/301212Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.