PT-2021-22727 · Gitlab · Gitlab Ce/Ee+1

·

CVE-2021-39881

·

Published

2021-10-05

·

Updated

2024-03-06

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 7.7 and later
Description: The application may allow a malicious user to create an OAuth client application with arbitrary scope names, potentially tricking unsuspecting users into authorizing the malicious client application using the spoofed scope name and description.
Recommendations: For GitLab CE/EE versions 7.7 and later, consider restricting the ability to create OAuth client applications with arbitrary scope names until a patch is available. As a temporary workaround, monitor OAuth client application creations and authorization requests to detect potential malicious activity.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-GITLAB-2021-39881
CVE-2021-39881

Affected Products

Gitlab
Gitlab Ce/Ee