First published: Mon Aug 23 2021(Updated: )
Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=12.2.0<13.12.9 | |
GitLab | >=14.0.0<14.0.7 | |
GitLab | >=14.1.0<14.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22251 is classified as a medium severity vulnerability.
To resolve CVE-2021-22251, upgrade to GitLab versions 13.12.10, 14.0.8, or 14.1.3 or later.
CVE-2021-22251 may allow unauthorized users to add members to projects using blocked email domains.
CVE-2021-22251 affects GitLab versions from 12.2.0 to 13.12.9, 14.0.0 to 14.0.7, and 14.1.0 to 14.1.2.
Currently, there is no official workaround for CVE-2021-22251; updating GitLab is recommended.