ZeroHour

CVE-2021-39872

CVSS 3.1
6.5 medium
EPSS
<1%p60
Published
()
Modified
Description

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.

Vendors
gitlab
Products
gitlab
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.