CVE Vulnerabilities

CVE-2021-22213

Published: Jun 08, 2021 | Modified: Jul 12, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 7.10.0 (including) 13.10.5 (excluding)
Gitlab Gitlab 13.11.0 (including) 13.11.5 (excluding)
Gitlab Gitlab 13.12.0 (including) 13.12.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu upstream *

References