ZeroHour

CVE-2021-22224

CVSS 3.1
6.5 medium
EPSS
<1%p57
Published
()
Modified
Description

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

Vendors
gitlab
Products
gitlab
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.