
Cloud Vulnerability DB
A community-led vulnerabilities database
An information disclosure vulnerability was identified in GitLab Enterprise Edition (EE) versions 13.11 and later, tracked as CVE-2021-22215. The vulnerability allowed project owners to inadvertently access information about members' on-call rotations in other projects, potentially exposing sensitive scheduling data (GitLab Security Release, NVD).
The vulnerability was classified as a low severity issue with a CVSS score of 2.7 (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N). The issue specifically affected the member removal process in GitLab EE, where the system inadvertently exposed on-call rotation information from other projects during the member removal operation (GitLab Security Release).
The vulnerability could result in unauthorized access to on-call rotation schedules, potentially exposing sensitive organizational scheduling information. While the impact was limited due to the requirement of project owner privileges, it still represented a breach of project isolation principles (GitLab Security Release).
The vulnerability required project owner privileges to exploit, indicating a relatively high barrier to entry for potential attackers. The issue was discovered internally by the GitLab team, and there were no reported instances of the vulnerability being exploited in the wild (GitLab Security Release).
GitLab addressed this vulnerability in their security releases 13.12.2, 13.11.5, and 13.10.5. Users were strongly recommended to upgrade their GitLab installations to one of these versions immediately to mitigate the risk (GitLab Security Release).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."