PT-2021-6754 · Gitlab · Gitlab Ce/Ee+1

Stanlyoncmon

·

Published

2021-08-25

·

Updated

2024-03-06

·

CVE-2021-22245

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to the fixed version
Description The issue is related to improper validation of commit author in GitLab, allowing an attacker to make several pages in a project impossible to view. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For GitLab CE/EE versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to commit author validation functionality until a patch is available.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-02146
BIT-GITLAB-2021-22245
CVE-2021-22245

Affected Products

Gitlab
Gitlab Ce/Ee