PT-2021-6693 · Gitlab · Gitlab Ce/Ee+1

Published

2021-07-01

·

Updated

2024-03-06

·

CVE-2021-22226

CVSS v2.0

7.9

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.9 and later
Description The issue allows certain users to push to protected branches that were restricted to deploy keys. This can be exploited by a remote attacker to access confidential data and compromise its integrity.
Recommendations For GitLab CE/EE versions 13.9 and later, update to a version that includes a fix for this issue to prevent unauthorized access to protected branches.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2022-02048
BIT-GITLAB-2021-22226
CVE-2021-22226

Affected Products

Gitlab
Gitlab Ce/Ee