CVE-2021-22252
23.08.2021, 20:15
A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which should only be accessible to MaintainersEnginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 13.7.0 ≤ 𝑥 < 13.12.9 |
gitlab | gitlab | 13.7.0 ≤ 𝑥 < 13.12.9 |
gitlab | gitlab | 14.0.0 ≤ 𝑥 < 14.0.7 |
gitlab | gitlab | 14.0.0 ≤ 𝑥 < 14.0.7 |
gitlab | gitlab | 14.1.0 ≤ 𝑥 < 14.1.2 |
gitlab | gitlab | 14.1.0 ≤ 𝑥 < 14.1.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References