CVE-2021-22236 Information
Jun 07, 2022
cve
Description
Due to improper handling of OAuth client IDs new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22236.json https://gitlab.com/gitlab-org/gitlab/-/issues/334925
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: