| Vulnerability Name: | CVE-2021-22251 (CCN-208010) | ||||||||||||
| Assigned: | 2021-08-23 | ||||||||||||
| Published: | 2021-08-23 | ||||||||||||
| Updated: | 2021-08-28 | ||||||||||||
| Summary: | Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings | ||||||||||||
| CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-863 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2021-22251 Source: XF Type: UNKNOWN gitlab-cve202122251-sec-bypass(208010) Source: CCN Type: GitLab Web site CVE-2021-22251.json Source: CONFIRM Type: Vendor Advisory https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json Source: MISC Type: Exploit, Issue Tracking, Vendor Advisory https://gitlab.com/gitlab-org/gitlab/-/issues/14004 Source: MISC Type: Permissions Required, Third Party Advisory https://hackerone.com/reports/679567 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||