PT-2021-14925 · Gitlab · Gitlab
Published
2021-10-05
·
Updated
2024-03-06
·
CVE-2021-22264
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
GitLab versions 13.8 through 14.0.9
GitLab versions 14.1 through 14.1.4
GitLab versions 14.2 through 14.2.2
Description:
An issue has been discovered in GitLab where, under specialized conditions, an invited group member may continue to have access to a project even after the invited group, which the member was part of, is deleted.
Recommendations:
For GitLab versions 13.8 through 14.0.9, update to version 14.0.9 or later to resolve the issue.
For GitLab versions 14.1 through 14.1.4, update to version 14.1.4 or later to resolve the issue.
For GitLab versions 14.2 through 14.2.2, update to version 14.2.2 or later to resolve the issue.
As a temporary workaround, consider reviewing and manually removing access for invited group members who should no longer have access to projects after their group has been deleted.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab