Vulnerability Description
A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token
CVSS Score
8.5
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 13.7.0, < 13.7.8 |
Related Weaknesses (CWE)
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22190.jsonThird Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/300281Broken Link
- https://hackerone.com/reports/1040786Permissions Required
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22190.jsonThird Party Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/300281Broken Link
- https://hackerone.com/reports/1040786Permissions Required
FAQ
What is CVE-2021-22190?
CVE-2021-22190 is a vulnerability with a CVSS score of 8.5 (HIGH). A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token
How severe is CVE-2021-22190?
CVE-2021-22190 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22190?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.