CVE-2021-39890Improper Authentication in Gitlab

Severity
9.8CRITICALNVD
EPSS
0.1%
top 81.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateDec 7

Description

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDgitlab/gitlab14.1.114.1.7+3
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=14.1.1, <14.1.7, >=14.2, <14.2.5, >=14.3, <14.3.1+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-45jj-6gxc-rh25: It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 142021-12-07
OSV
CVE-2021-39890: It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 142021-12-06

📋Vendor Advisories

2
GitLab
CVE-2021-39890: It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.2021-12-06
Debian
CVE-2021-39890: gitlab - It was possible to bypass 2FA for LDAP users and access some specific pages with...2021