QID 375401

Date Published: 2021-04-05

QID 375401: Gitlab Group Maintainers Unrestricted Access Vulnerability (gitlab-13-9-2)

GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.

CVE-2021-22186 - An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables which should be restricted to group owners.

Affected Versions:
GitLab Community Edition (CE) and Enterprise Edition (EE):
GitLab CE/EE version version 9.4 and up, and prior to patch versions 13.9.2, 13.8.5 and 13.7.8

QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.

Successful exploitation could affect confidentiality and integrity.

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    The vendor has released patch, For more information please visit gitlab-13-9-2
    Vendor References

    CVEs related to QID 375401

    Software Advisories
    Advisory ID Software Component Link
    gitlab-13-9-2 URL Logo about.gitlab.com/releases/2021/03/04/security-release-gitlab-13-9-2-released/