CVE-2021-22172
26.03.2021, 20:15
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases pageEnginsight
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 12.8.0 ≤ 𝑥 < 13.6.6 |
| gitlab | gitlab | 12.8.0 ≤ 𝑥 < 13.6.6 |
| gitlab | gitlab | 13.7.0 ≤ 𝑥 < 13.7.6 |
| gitlab | gitlab | 13.7.0 ≤ 𝑥 < 13.7.6 |
| gitlab | gitlab | 13.8.0 ≤ 𝑥 < 13.8.2 |
| gitlab | gitlab | 13.8.0 ≤ 𝑥 < 13.8.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References