CVE-2021-22237 log

Source
Severity Medium
Remote Yes
Type Access restriction bypass
Description
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab versions before 14.1.2.
Group Package Affected Fixed Severity Status Ticket
AVG-2251 gitlab 14.1.1-1 14.1.2-1 High Fixed
Date Advisory Group Package Severity Type
10 Aug 2021 ASA-202108-7 AVG-2251 gitlab High multiple issues
References
https://about.gitlab.com/releases/2021/08/03/security-release-gitlab-14-1-2-released/#perform-git-actions-with-an-impersonation-token-even-if-impersonation-is-disabled