Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/300265 | broken link |
https://hackerone.com/reports/1087806 | third party advisory permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22254.json | vendor advisory |