ZeroHour

CVE-2021-22236

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
Description

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

Vendors
gitlab
Products
gitlab
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.