High severity7.1NVD Advisory· Published Jul 7, 2021· Updated Jun 17, 2026
CVE-2021-22224
CVE-2021-22224
Description
A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: >=13.12.0,<13.12.6
- (no CPE)range: 13.12 <= versions < 13.12.6, 14.0 < versions < 14.0.2
- (no CPE)range: >=13.12, <13.12.6
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22224.jsonnvdThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/324397nvdBroken Link
- hackerone.com/reports/1122408nvdPermissions Required
News mentions
0No linked articles in our index yet.