CVE-2021-22198 - log back

CVE-2021-22198 edited at 03 Apr 2021 09:08:39
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Access restriction bypass
Description
+ An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects. The issue is fixed in GitLab versions 13.10.1, 13.9.5 and 13.8.7.
References
+ https://about.gitlab.com/releases/2021/03/31/security-release-gitlab-13-10-1-released/#incident-metric-images-can-be-deleted-by-any-user
+ https://gitlab.com/gitlab-org/gitlab/-/issues/323452
+ https://hackerone.com/reports/1107281
Notes
CVE-2021-22198 created at 03 Apr 2021 09:03:52