CVE-2021-22262 Information
Jun 07, 2022
cve
Description
Missing access control in all GitLab versions starting from 13.12 before 14.0.9 all versions starting from 14.1 before 14.1.4 and all versions starting from 14.2 before 14.2.2 with Jira Cloud integration enabled allows Jira users without administrative privileges to add and remove Jira Connect Namespaces via the GitLab.com for Jira Cloud application configuration page
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Reference
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22262.json https://gitlab.com/gitlab-org/gitlab/-/issues/327062 https://hackerone.com/reports/1147812
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.3
Share on: