### [CVE-2021-22198](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22198) ![](https://img.shields.io/static/v1?label=Product&message=GitLab&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3E%3D13.10%2C%20%3C13.10.1%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=%3E%3D13.8%2C%20%3C13.8.7%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=%3E%3D13.9%2C%20%3C13.9.5%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20access%20control%20in%20GitLab&color=brightgreen) ### Description An issue has been discovered in GitLab CE/EE affecting all versions from 13.8 and above allowing an authenticated user to delete incident metric images of public projects. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0xfschott/CVE-search