PT-2021-4078 · Gitlab · Gitlab

Published

2021-01-05

·

Updated

2024-03-06

·

CVE-2021-22208

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 13.5 through 13.9.7
Description The issue is related to improper permission checks in GitLab, which could allow an attacker to change the timestamp for issue creation or update. This may impact the integrity of the data.
Recommendations For GitLab versions 13.5 through 13.9.7, update to a version that includes the fix for this issue to prevent exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-04656
BIT-GITLAB-2021-22208
CVE-2021-22208

Affected Products

Gitlab