CVE-2021-22218

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
gitlabgitlab
12.8.0 ≤
𝑥
< 13.10.5
gitlabgitlab
12.8.0 ≤
𝑥
< 13.10.5
gitlabgitlab
13.11.0 ≤
𝑥
< 13.11.5
gitlabgitlab
13.11.0 ≤
𝑥
< 13.11.5
gitlabgitlab
13.12.0 ≤
𝑥
< 13.12.2
gitlabgitlab
13.12.0 ≤
𝑥
< 13.12.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gitlab
sid
16.8.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gitlab
focal
dne
jammy
dne
mantic
dne
noble
dne
xenial
not-affected