PT-2021-22727 · Gitlab · Gitlab Ce/Ee+1
Executor
·
Published
2021-10-05
·
Updated
2024-03-06
·
CVE-2021-39881
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
GitLab CE/EE versions 7.7 and later
Description:
The application may allow a malicious user to create an OAuth client application with arbitrary scope names, potentially tricking unsuspecting users into authorizing the malicious client application using the spoofed scope name and description.
Recommendations:
For GitLab CE/EE versions 7.7 and later, consider restricting the ability to create OAuth client applications with arbitrary scope names until a patch is available. As a temporary workaround, monitor OAuth client application creations and authorization requests to detect potential malicious activity.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee