Related Vulnerabilities: CVE-2021-22239  

An unauthorized user was able to insert metadata when creating new issue on GitLab 14.0 and later before version 14.1.2.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

An unauthorized user was able to insert metadata when creating new issue on GitLab 14.0 and later before version 14.1.2.

AVG-2251 gitlab 14.1.1-1 Medium Vulnerable

https://about.gitlab.com/releases/2021/08/03/security-release-gitlab-14-1-2-released/#unauthorised-user-was-able-to-add-meta-data-upon-issue-creation