CVE-2021-22208 - log back

CVE-2021-22208 edited at 06 May 2021 17:32:11
References
https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#non-owners-can-set-system_note_timestamp-when-creating--updating-issues
+ https://gitlab.com/gitlab-org/gitlab/-/issues/301212
CVE-2021-22208 edited at 28 Apr 2021 11:07:02
Description
- An issue has been discovered in GitLab affecting versions prior to 13.5. Improper permission check could allow the change of timestamp for issue creation or update.
+ An issue has been discovered in GitLab affecting versions prior to 13.5. Improper permission check could allow the change of timestamp for issue creation or update. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7.
CVE-2021-22208 edited at 28 Apr 2021 11:02:19
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Access restriction bypass
Description
+ An issue has been discovered in GitLab affecting versions prior to 13.5. Improper permission check could allow the change of timestamp for issue creation or update.
References
+ https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#non-owners-can-set-system_note_timestamp-when-creating--updating-issues
Notes
CVE-2021-22208 created at 28 Apr 2021 10:57:49