Medium severity5.4NVD Advisory· Published Aug 25, 2021· Updated Jun 17, 2026
CVE-2021-22250
CVE-2021-22250
Description
Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=13.3.0,<13.12.9
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.3.0,<13.12.9
- (no CPE)range: since 13.3
- (no CPE)range: >=13.3, <13.12.9
- Range: since 13.3
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22250.jsonnvdVendor Advisory
- hackerone.com/reports/1205916nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/332410nvdBroken Link
News mentions
0No linked articles in our index yet.