Lucene search

K
cvelistGitLabCVELIST:CVE-2021-22224
HistoryJul 07, 2021 - 11:26 a.m.

CVE-2021-22224

2021-07-0711:26:37
GitLab
www.cve.org
5
cve-2021-22224
gitlab
graphql
api
vulnerability
version 13.12
version 14.0.2
attacker
mutation

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

28.0%

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CNA Affected

[
  {
    "product": "GitLab",
    "vendor": "GitLab",
    "versions": [
      {
        "status": "affected",
        "version": ">=13.12, <13.12.6"
      },
      {
        "status": "affected",
        "version": ">=14.0, <14.0.2"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

28.0%