CVE-2021-22218

low

Description

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

References

https://hackerone.com/reports/1077019

https://gitlab.com/gitlab-org/gitlab/-/issues/297665

https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22218.json

Details

Source: Mitre, NVD

Published: 2021-06-08

Updated: 2022-07-22

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 2.6

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

Severity: Low