An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.
2021-05-06T13:15:11.300
2024-11-21T05:49:43.123
Modified
CVSSv3.1: 3.1 (LOW)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 13.9.7 | Yes |
Application | gitlab | gitlab | < 13.9.7 | Yes |
Application | gitlab | gitlab | < 13.10.4 | Yes |
Application | gitlab | gitlab | < 13.10.4 | Yes |
Application | gitlab | gitlab | < 13.11.2 | Yes |
Application | gitlab | gitlab | < 13.11.2 | Yes |