ZeroHour

CVE-2021-39881

CVSS 3.1
3.5 low
EPSS
<1%p57
Published
()
Modified
Description

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

Vendors
gitlab
Products
gitlab
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.