CVE-2021-39872 Information
Jun 07, 2022
cve
Description
In all versions of GitLab CE/EE since version 14.1 an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39872.json https://hackerone.com/reports/1285226 https://gitlab.com/gitlab-org/gitlab/-/issues/337954
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: