CVE-2021-22224

Source
https://cve.org/CVERecord?id=CVE-2021-22224
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-22224.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-22224
Aliases
Downstream
Published
2021-07-07T12:15:08.310Z
Modified
2026-03-14T15:17:21.376436Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "13.12.0"
        },
        {
            "fixed": "13.12.6"
        },
        {
            "introduced": "14.0.0"
        },
        {
            "fixed": "14.0.2"
        }
    ]
}

Affected versions

v13.*
v13.12.0-ee
v13.12.1-ee
v13.12.2-ee
v13.12.3-ee
v13.12.4-ee
v13.12.5-ee
v14.*
v14.0.0-ee
v14.0.1-ee

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-22224.json"