CVE-2021-22176

MEDIUM

GitLab 3.0.1-13.6.7 - Incorrect Authorization for Demoted Project Members

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab/-/issues/243491
Issue Tracking, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/962604

Scores

CVSS v3 4.3
EPSS 0.0010
EPSS Percentile 27.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-863
Status published
Products (1)
gitlab/gitlab 3.0.1 - 13.6.7 (2 CPE variants)
Published Mar 24, 2021
Tracked Since Feb 18, 2026