CVE-2021-22251 — Incorrect Authorization in Gitlab
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 55.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 23
Latest updateMay 24
Description
Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2021-22251: Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address↗2021-08-23
Debian▶
CVE-2021-22251: gitlab - Improper validation of invited users' email address in GitLab EE affecting all v...↗2021