VYPR
Medium severity4.3NVD Advisory· Published Mar 24, 2021· Updated Jun 17, 2026

CVE-2021-22176

CVE-2021-22176

Description

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=3.0.1,<13.6.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=3.0.1,<13.6.7
    • (no CPE)range: >=3.0.1
    • (no CPE)range: >=13.8.0, <13.8.4
  • osv-coords
    Range: >= 3.0.1, < 13.6.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.