PT-2021-6483 · Gitlab · Gitlab Ce/Ee+1

·

CVE-2021-22229

·

Published

2021-07-06

·

Updated

2024-03-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 12.8 and later
Description An issue has been discovered affecting GitLab CE/EE, where under a special condition, it was possible to access data of an internal repository through a project fork done by a project member. The issue is related to insufficient access restrictions to a forked project, allowing a remote attacker to gain access to confidential data.
Recommendations For GitLab CE/EE versions 12.8 and later, consider restricting access to project forks to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the permissions of project members to prevent unauthorized access to internal repository data.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01732
BIT-GITLAB-2021-22229
CVE-2021-22229

Affected Products

Gitlab
Gitlab Ce/Ee