PT-2021-22727 · Gitlab · Gitlab Ce/Ee+1

Executor

·

Published

2021-10-05

·

Updated

2024-03-06

·

CVE-2021-39881

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 7.7 and later
Description: The application may allow a malicious user to create an OAuth client application with arbitrary scope names, potentially tricking unsuspecting users into authorizing the malicious client application using the spoofed scope name and description.
Recommendations: For GitLab CE/EE versions 7.7 and later, consider restricting the ability to create OAuth client applications with arbitrary scope names until a patch is available. As a temporary workaround, monitor OAuth client application creations and authorization requests to detect potential malicious activity.

Fix

Related Identifiers

BIT-GITLAB-2021-39881
CVE-2021-39881

Affected Products

Gitlab
Gitlab Ce/Ee