CVE-2021-39872

MEDIUM

GitLab >=14.1.0 <14.1.7 - Improper Access Control via Expired Password Bypass

Title source: llm
STIX 2.1

Description

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1285226

Scores

CVSS v3 6.5
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (2)
gitlab/gitlab 4.3.0 (2 CPE variants)
gitlab/gitlab 14.1.0 - 14.1.7 (2 CPE variants)
Published Oct 05, 2021
Tracked Since Feb 18, 2026