Cross-Site Request Forgery Vulnerability in GitLab GraphQL API Allows Unauthorized Mutation Calls

Cross-Site Request Forgery Vulnerability in GitLab GraphQL API Allows Unauthorized Mutation Calls

CVE-2021-22224 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

Learn more about our Api Penetration Testing.