CVE-2021-22209 - log back

CVE-2021-22209 edited at 06 May 2021 17:32:28
References
https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#read-api-scoped-tokens-can-execute-mutations
+ https://gitlab.com/gitlab-org/gitlab/-/issues/327155
CVE-2021-22209 edited at 28 Apr 2021 11:07:08
Description
- An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.
+ An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed. The issue is fixed in GitLab versions 13.11.2, 13.10.4 and 13.9.7.
CVE-2021-22209 edited at 28 Apr 2021 11:03:54
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Insufficient validation
Description
+ An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.
References
+ https://about.gitlab.com/releases/2021/04/28/security-release-gitlab-13-11-2-released/#read-api-scoped-tokens-can-execute-mutations
Notes
CVE-2021-22209 created at 28 Apr 2021 10:57:49