VYPR
Medium severity4.3NVD Advisory· Published Oct 5, 2021· Updated Jun 17, 2026

CVE-2021-22258

CVE-2021-22258

Description

The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.9.0,<14.0.9
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.9.0,<14.0.9
    • (no CPE)range: >=8.9
    • (no CPE)range: >=14.2, <14.2.2
  • osv-coords
    Range: >= 8.9.0, < 14.0.9

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.