CVE-2021-22253

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/08/2021
Last modified:
30/08/2021

Description

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 13.4.0 (including) 13.12.9 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 13.4.0 (including) 13.12.9 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 14.0.0 (including) 14.0.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 14.0.0 (including) 14.0.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 14.1.0 (including) 14.1.2 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 14.1.0 (including) 14.1.2 (excluding)