Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-22251


Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings


Published

2021-08-23T20:15:12.830

Last Modified

2024-11-21T05:49:47.730

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 13.12.9 Yes
Application gitlab gitlab < 14.0.7 Yes
Application gitlab gitlab < 14.1.2 Yes

References