VulnerabilityModified
CVE-2021-39872
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
MEDIUM 6.5EPSS 0.99%
Does this matter?
Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.
Description
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.99% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39872.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/337954Broken Link
- https://hackerone.com/reports/1285226Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39872.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/337954Broken Link
- https://hackerone.com/reports/1285226Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.