CVE-2021-22240 Information

Description

Improper access control in GitLab EE versions 13.11.6 13.12.6 and 14.0.2 allows users to be created via single sign on despite user cap being enabled

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Reference

https://gitlab.com/gitlab-org/gitlab/-/issues/327641 https://hackerone.com/reports/1166566 https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22240.json

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

Share on: