An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access control allows unauthorised users to access project details using Graphql.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22228.json | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/332605 | Exploit Issue Tracking Patch Vendor Advisory |
https://hackerone.com/reports/1192460 | Exploit Issue Tracking Third Party Advisory |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22228.json | Vendor Advisory |
https://gitlab.com/gitlab-org/gitlab/-/issues/332605 | Exploit Issue Tracking Patch Vendor Advisory |
https://hackerone.com/reports/1192460 | Exploit Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22228.json - Vendor Advisory | |
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/332605 - Exploit, Issue Tracking, Patch, Vendor Advisory | |
References | () https://hackerone.com/reports/1192460 - Exploit, Issue Tracking, Third Party Advisory |
Information
Published : 2021-07-06 22:15
Updated : 2024-11-21 05:49
NVD link : CVE-2021-22228
Mitre link : CVE-2021-22228
CVE.ORG link : CVE-2021-22228
JSON object : View
Products Affected
gitlab
- gitlab
CWE