CVE-2021-22241 |
High |
Yes |
Cross-site scripting |
An issue has been discovered in GitLab affecting all versions starting from 13.4 and before 14.1.2. It was possible to exploit a stored cross-site-scripting... |
CVE-2021-22239 |
Medium |
Yes |
Access restriction bypass |
An unauthorized user was able to insert metadata when creating a new issue on GitLab 14.0 and later before version 14.1.2. |
CVE-2021-22237 |
Medium |
Yes |
Access restriction bypass |
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This... |
CVE-2021-22236 |
Medium |
Yes |
Incorrect calculation |
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is... |