CVE-2021-22218

LOW

GitLab 12.8-13.10.4, 13.11-13.11.4, 13.12-13.12.1 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed commits.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1077019

Scores

CVSS v3 2.6
EPSS 0.0013
EPSS Percentile 31.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-295
Status published
Products (1)
gitlab/gitlab 12.8.0 - 13.10.5 (2 CPE variants)
Published Jun 08, 2021
Tracked Since Feb 18, 2026