Log

CVE-2021-22215 edited at 08 Jun 2021 17:00:30
Description
- An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects.
+ An information disclosure vulnerability in GitLab EE versions 13.11 and later before 13.12.2 allowed a project owner to leak information about the members' on-call rotations in other projects.
References
https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
https://gitlab.com/gitlab-org/gitlab/-/issues/328668
CVE-2021-22214 edited at 08 Jun 2021 17:00:16
Description
- When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited.
+ When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 before 13.12.2 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited.
References
https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
https://gitlab.com/gitlab-org/gitlab/-/issues/322926
https://hackerone.com/reports/1110131
CVE-2021-22213 edited at 08 Jun 2021 16:59:57
Description
- A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari.
+ A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 before 13.12.2 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari.
References
https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
https://gitlab.com/gitlab-org/gitlab/-/issues/300308
https://hackerone.com/reports/1089277
CVE-2021-22181 edited at 08 Jun 2021 16:59:44
References
- https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/#denial-of-service-through-recursive-triggered-pipelines
+ https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
AVG-2023 edited at 08 Jun 2021 16:58:09
Issues
CVE-2021-22181
CVE-2021-22213
CVE-2021-22214
CVE-2021-22215
CVE-2021-22216
CVE-2021-22217
CVE-2021-22218
+ CVE-2021-22219
CVE-2021-22220
CVE-2021-22221
CVE-2021-22218 edited at 08 Jun 2021 16:56:55
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Content spoofing
Description
+ All versions of GitLab CE/EE starting with 12.8 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.
References
+ https://gitlab.com/gitlab-org/gitlab/-/issues/297665
+ https://hackerone.com/reports/1077019
CVE-2021-22221 edited at 08 Jun 2021 16:55:45
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Authentication bypass
Description
+ An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired.
References
+ https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
+ https://gitlab.com/gitlab-org/gitlab/-/issues/292006
CVE-2021-22220 edited at 08 Jun 2021 16:55:45
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site scripting
Description
+ An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored cross-site scripting (XSS) attack in blob viewer of notebooks.
References
+ https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
+ https://gitlab.com/gitlab-org/gitlab/-/issues/294128
+ https://hackerone.com/reports/1060114
CVE-2021-22219 created at 08 Jun 2021 16:55:44
Severity
+ Medium
Remote
+ Remote
Type
+ Information disclosure
Description
+ GitLab CE/EE since version 9.5 allows a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
References
+ https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
+ https://gitlab.com/gitlab-org/gitlab/-/issues/296995
Notes
CVE-2021-22217 edited at 08 Jun 2021 16:55:44
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resource consumption with a specially crafted issue or merge request.
References
+ https://about.gitlab.com/releases/2021/06/01/security-release-gitlab-13-12-2-released/
+ https://gitlab.com/gitlab-org/gitlab/-/issues/300709
+ https://hackerone.com/reports/1090049