CVE-2021-22192
critical · 9.9An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.
9.9
CVSS
13.1%
EPSS (exploit prob.)
96th
EPSS percentile
2021-03-24
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gitlab | gitlab | >= 13.2.0, < 13.7.9 |
| gitlab | gitlab | >= 13.2.0, < 13.7.9 |
| gitlab | gitlab | >= 13.8.0, < 13.8.6 |
| gitlab | gitlab | >= 13.8.0, < 13.8.6 |
| gitlab | gitlab | >= 13.9.0, < 13.9.4 |
| gitlab | gitlab | >= 13.9.0, < 13.9.4 |
Check a specific version with /api/v1/cve/match.
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22192.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/324452
- https://hackerone.com/reports/1125425
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22192.json
- https://gitlab.com/gitlab-org/gitlab/-/issues/324452
- https://hackerone.com/reports/1125425
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-22192