Vulnerabilities > CVE-2021-22253 - Incorrect Authorization vulnerability in Gitlab

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
LOW
network
low complexity
gitlab
CWE-863

Summary

Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed

Vulnerable Configurations

Part Description Count
Application
Gitlab
160

Common Weakness Enumeration (CWE)