VYPR
Medium severity6.6NVD Advisory· Published Aug 25, 2021· Updated Jun 17, 2026

CVE-2021-22237

CVE-2021-22237

Description

Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.1.0,<13.12.9
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.1.0,<13.12.9
    • (no CPE)range: <13.12.9, 14.0.7, 14.1.2
    • (no CPE)range: >=13.1, <13.12.9
  • osv-coords
    Range: >= 13.1.0, < 13.12.9

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.