Oqt+3CCVE-2021-22193

CVE-2021-22193
GitLab 5FOqC0

6/dCYd

An information disclosure vulnerability (CVE-2021-22193) was discovered in GitLab affecting all versions starting from 7.1. The vulnerability allowed a member of a private group to validate the existence of a specific name for a private project, potentially leading to unauthorized information disclosure (GitLab Release, NVD).

69Gavs

The vulnerability has been assigned a CVSS v3.1 Base Score of 3.5 (LOW) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N. The issue is classified under CWE-209 (Generation of Error Message Containing Sensitive Information). The vulnerability affects both GitLab Community and Enterprise editions, versions from 7.1.0 up to (excluding) 13.8.2 (NVD).

k4I7F8

The vulnerability could allow attackers to determine the existence of private projects within GitLab groups, leading to potential privacy breaches and information disclosure about confidential project names (GitLab Release).

Cv1hTD

GitLab has addressed this vulnerability in versions 13.8.2, 13.7.6, and 13.6.6. Users are strongly recommended to upgrade to these or later versions immediately to mitigate the security risk (GitLab Release).

eODNrw


wdxz7KlXzpe4

Sn+yiv

yRZyYq

BDHA/i

Eq6YVV

qBL0qL

3pJ7V5

yd/Ltz

LfWFUw

MefUT7

CVE-2024-9183HIGH7.7
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab
1UzENPl75CjTDec 05, 2025
CVE-2025-7449MEDIUM6.5
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
1UzENPl75CjTNov 26, 2025
CVE-2025-12653MEDIUM6.5
  • GitLabGitLab
  • gitlab
1UzENPl75CjTNov 26, 2025
CVE-2025-13611MEDIUM5.3
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
1UzENPl75CjTNov 26, 2025
CVE-2025-6195MEDIUM4.3
  • GitLabGitLab
  • gitlab
1UzENPl75CjTNov 26, 2025

0Y8wfh

fX1rcP

Rkx7gz

lVlJIo

hg51QW

Rm1gZh

v5ktBc

"shq3dj"
htk05AkgqPHn
"hFkAdK"
3uy78sXKvT9s
"KLylDc"
hanb5o7KXyr8