← Back

CVE-2021-22251

nvd nist
Published: Aug 23, 2021Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

Affected (3)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 12.2.0 to 13.12.9
From 14.0.0 to 14.0.7
From 14.1.0 to 14.1.2

References (6)

Source: cve@gitlab.com
ExploitIssue TrackingVendor Advisory
Source: cve@gitlab.com
Permissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredThird Party Advisory

Timeline

No history available yet.