CVE-2021-39881
Last modified
CVE-2021-39881 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 7.7.0, < 14.1.7 |
| Gitlab | Gitlab | >= 14.2.0, < 14.2.5 |
| Gitlab | Gitlab | >= 14.3.0, < 14.3.1 |
References
- https://hackerone.com/reports/494530Permissions Required, Third Party Advisory
- https://hackerone.com/reports/494530Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-39881?
How severe is CVE-2021-39881?
How do I fix CVE-2021-39881?
Are you affected by CVE-2021-39881?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
