PT-2021-4089 · Gitlab · Gitlab

Published

2021-01-05

·

Updated

2024-03-06

·

CVE-2021-22221

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 12.9.0 through 13.10.5 GitLab versions 13.11.0 through 13.11.5 GitLab versions 13.12.0 through 13.12.2
Description The issue is related to insufficient expired password validation in various operations, allowing a user to maintain limited access after their password has expired. This could potentially enable a remote attacker to access confidential data and compromise its integrity.
Recommendations For GitLab versions 12.9.0 through 13.10.5, update to version 13.10.5 or later. For GitLab versions 13.11.0 through 13.11.5, update to version 13.11.5 or later. For GitLab versions 13.12.0 through 13.12.2, update to version 13.12.2 or later.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BDU:2021-04667
BIT-GITLAB-2021-22221
CVE-2021-22221

Affected Products

Gitlab