CVE-2021-22224 - log back

CVE-2021-22224 created at 06 Jul 2021 17:46:39
Severity
+ High
Remote
+ Remote
Type
+ Cross-site request forgery
Description
+ A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before version 14.0.2 allowed an attacker to call mutations as the victim.
References
+ https://gitlab.com/gitlab-org/gitlab/-/issues/324397
+ https://hackerone.com/reports/1122408
+ https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22224.json
Notes