CVE-2021-22208 log

Source
Severity Medium
Remote Yes
Type Access restriction bypass
Description
An issue has been discovered in GitLab affecting versions prior to 13.5. Improper permission check could allow the change of timestamp for issue creation or update. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7.
Group Package Affected Fixed Severity Status Ticket
AVG-1888 gitlab 13.10.3-2 13.10.4-1 High Fixed
References
https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#non-owners-can-set-system_note_timestamp-when-creating--updating-issues
https://gitlab.com/gitlab-org/gitlab/-/issues/301212