CVE-2021-22239 log

Source
Severity Medium
Remote Yes
Type Access restriction bypass
Description
An unauthorized user was able to insert metadata when creating a new issue on GitLab 14.0 and later before version 14.1.2.
Group Package Affected Fixed Severity Status Ticket
AVG-2251 gitlab 14.1.1-1 14.1.2-1 High Fixed
Date Advisory Group Package Severity Type
10 Aug 2021 ASA-202108-7 AVG-2251 gitlab High multiple issues
References
https://about.gitlab.com/releases/2021/08/03/security-release-gitlab-14-1-2-released/#unauthorised-user-was-able-to-add-meta-data-upon-issue-creation