CVE-2021-22251: Input Validation
Published Aug 23, 2021
·Updated
Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings
Affected Software
3 affected components
GitLab GitLab>=12.2.0<13.12.9
GitLab GitLab>=14.0.0<14.0.7
GitLab GitLab>=14.1.0<14.1.2
Event History
Aug 23, 2021
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22251?
CVE-2021-22251 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-22251?
To resolve CVE-2021-22251, upgrade to GitLab versions 13.12.10, 14.0.8, or 14.1.3 or later.
3
What are the consequences of CVE-2021-22251?
CVE-2021-22251 may allow unauthorized users to add members to projects using blocked email domains.
4
Which versions of GitLab are affected by CVE-2021-22251?
CVE-2021-22251 affects GitLab versions from 12.2.0 to 13.12.9, 14.0.0 to 14.0.7, and 14.1.0 to 14.1.2.
5
Is there a workaround for CVE-2021-22251?
Currently, there is no official workaround for CVE-2021-22251; updating GitLab is recommended.