CVE-2021-22263

MEDIUM

GitLab 13.0-14.0.8, 14.1-14.1.3, 14.2-14.2.1 - Privilege Escalation via Project Token Abuse

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting from 14.1 before 14.1.4, all versions starting from 14.2 before 14.2.2. A user account with 'external' status which is granted 'Maintainer' role on any project on the GitLab instance where 'project tokens' are allowed may elevate its privilege to 'Internal' and access Internal projects.

References (3)

Core 3
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
https://gitlab.com/gitlab-org/gitlab/-/issues/331473
Exploit, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1193062

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-269
Status published
Products (1)
gitlab/gitlab 13.0.0 - 14.0.9 (2 CPE variants)
Published Oct 11, 2021
Tracked Since Feb 18, 2026