CVE-2021-22209 log
Source |
|
Severity | High |
Remote | Yes |
Type | Insufficient validation |
Description | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1888 | gitlab | 13.10.3-2 | 13.10.4-1 | High | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
19 May 2021 | ASA-202105-4 | AVG-1888 | gitlab | High | multiple issues |
References |
---|
https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#read-api-scoped-tokens-can-execute-mutations https://gitlab.com/gitlab-org/gitlab/-/issues/327155 |