First published: Wed Aug 25 2021(Updated: )
Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=7.10.0<13.12.9 | |
GitLab | >=7.10.0<13.12.9 | |
GitLab | >=14.0.0<14.0.7 | |
GitLab | >=14.0.0<14.0.7 | |
GitLab | >=14.1.0<14.1.2 | |
GitLab | >=14.1.0<14.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22243 is classified as a medium severity vulnerability that can allow unauthorized access to groups.
To mitigate CVE-2021-22243, upgrade GitLab to the latest version that contains the security fix.
GitLab CE/EE versions from 7.10 to 14.1.2 are affected by CVE-2021-22243.
CVE-2021-22243 allows existing GitLab users to access groups using invite URLs meant for different email addresses.
There are no publicly reported exploits specifically targeting CVE-2021-22243, but it poses a security risk if left unpatched.