CVE-2021-22240

MEDIUM

GitLab 13.7.0-13.11.6 - Incorrect Authorization via Single Sign-On User Creation

Title source: llm
STIX 2.1

Description

Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1166566

Scores

CVSS v3 4.2
EPSS 0.0023
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-863
Status published
Products (1)
gitlab/gitlab 13.7.0 - 13.11.6
Published Aug 05, 2021
Tracked Since Feb 18, 2026