VulnerabilityModified
CVE-2021-22240
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled
MEDIUM 4.3EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22240.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/327641Broken Link
- https://hackerone.com/reports/1166566Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22240.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/327641Broken Link
- https://hackerone.com/reports/1166566Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.