Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-22215
GitLab vulnerability analysis and mitigation

Overview

An information disclosure vulnerability was identified in GitLab Enterprise Edition (EE) versions 13.11 and later, tracked as CVE-2021-22215. The vulnerability allowed project owners to inadvertently access information about members' on-call rotations in other projects, potentially exposing sensitive scheduling data (GitLab Security Release, NVD).

Technical details

The vulnerability was classified as a low severity issue with a CVSS score of 2.7 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N). The issue specifically affected the member removal process in GitLab EE, where the system inadvertently exposed on-call rotation information from other projects during the member removal operation (GitLab Security Release).

Impact

The vulnerability could result in unauthorized access to on-call rotation schedules, potentially exposing sensitive organizational scheduling information. While the impact was limited due to the requirement of project owner privileges, it still represented a breach of project isolation principles (GitLab Security Release).

Exploitability

The vulnerability required project owner privileges to exploit, indicating a relatively high barrier to entry for potential attackers. The issue was discovered internally by the GitLab team, and there were no reported instances of the vulnerability being exploited in the wild (GitLab Security Release).

Mitigation and workarounds

GitLab addressed this vulnerability in their security releases 13.12.2, 13.11.5, and 13.10.5. Users were strongly recommended to upgrade their GitLab installations to one of these versions immediately to mitigate the risk (GitLab Security Release).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Arch Linux

Fixed

rolling

gitlab: 13.12.2-1

Fixed

SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-79708HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-78252HIGH8.2
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-86341MEDIUM4.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-8030MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-7514MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management