In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 14.1.0 (including) | 14.1.7 (excluding) |
Gitlab | Gitlab | 14.2.0 (including) | 14.2.5 (excluding) |
Gitlab | Gitlab | 4.3.0 (including) | 4.3.0 (including) |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | xenial | * |