CVE-2021-22251Incorrect Authorization in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 55.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 24

Description

Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab12.2.013.12.9+2
CVEListV5gitlab/gitlab>=12.2, <13.12.9, >=14.0, <14.0.7, >=14.1, <14.1.2+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-5f6w-rj6x-7j7v: Improper validation of invited users' email address in GitLab EE affecting all versions since 122022-05-24
OSV
CVE-2021-22251: Improper validation of invited users' email address in GitLab EE affecting all versions since 122021-08-23

📋Vendor Advisories

2
GitLab
CVE-2021-22251: Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address2021-08-23
Debian
CVE-2021-22251: gitlab - Improper validation of invited users' email address in GitLab EE affecting all v...2021