CVE-2021-22243

MEDIUM

GitLab 7.10.0-13.12.8 - Incorrect Authorization via Invite URL

Title source: llm
STIX 2.1

Description

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

References (2)

Core 2
Core References

Scores

CVSS v3 5.0
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-863
Status published
Products (1)
gitlab/gitlab 7.10.0 - 13.12.9 (2 CPE variants)
Published Aug 25, 2021
Tracked Since Feb 18, 2026