Low severity2.6NVD Advisory· Published Jun 8, 2021· Updated Jun 17, 2026
CVE-2021-22218
CVE-2021-22218
Description
All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=12.8.0,<13.10.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.8.0,<13.10.5
- (no CPE)range: 12.8 <= v < 13.10.5, 13.11 <= v < 13.11.5, 13.12 <= v < 13.12.2
- (no CPE)range: >=12.8, <13.10.5
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22218.jsonnvdVendor Advisory
- hackerone.com/reports/1077019nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/297665nvdBroken Link
News mentions
0No linked articles in our index yet.