PT-2021-6751 · Gitlab · Gitlab Ce/Ee+1

Ledz1996

·

Published

2021-08-20

·

Updated

2024-03-06

·

CVE-2021-22254

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.1 through 14.1.2 GitLab CE/EE version 14.0.7 GitLab CE/EE version 13.12.9
Description The issue is related to a lack of proper output encoding or escaping in GitLab, a platform for collaborative code development. Under specific conditions, a user could be impersonated using GitLab shell. This allows a remote attacker to gain access to confidential data.
Recommendations For GitLab CE/EE versions 13.1 through 14.1.2, update to a version outside of this range to resolve the issue. For GitLab CE/EE version 14.0.7, update to a newer version to mitigate the risk. For GitLab CE/EE version 13.12.9, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the GitLab shell until a patch is available.

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

BDU:2022-02142
BIT-GITLAB-2021-22254
CVE-2021-22254

Affected Products

Gitlab
Gitlab Ce/Ee