PT-2019-6205 · Gitlab · Gitlab Ce/Ee+1

Ashish_R_Padelkar

·

Published

2019-08-22

·

Updated

2024-03-06

·

CVE-2021-22251

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 12.2 and later
Description The issue is related to improper validation of invited users' email addresses, allowing projects to add members with email address domains that should be blocked by group settings. This can be exploited by a remote attacker to impact data integrity.
Recommendations For GitLab EE versions 12.2 and later, update to a version that includes the fix for the improper validation of invited users' email addresses. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02144
BIT-GITLAB-2021-22251
CVE-2021-22251

Affected Products

Gitlab
Gitlab Ce/Ee