PT-2021-6602 · Gitlab · Gitlab Ce/Ee+1

Rodrigopetteron

·

Published

2021-08-23

·

Updated

2024-03-06

·

CVE-2021-22252

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.7 and later
Description The issue is related to a confusion between tag and branch names in GitLab, allowing a remote attacker to access confidential data. Specifically, it enables a Developer to access protected CI variables that should only be accessible to Maintainers.
Recommendations For GitLab CE/EE versions 13.7 and later, update to a version that includes the fix for this issue to prevent unauthorized access to protected CI variables. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2022-01868
BIT-GITLAB-2021-22252
CVE-2021-22252

Affected Products

Gitlab
Gitlab Ce/Ee