ZeroHour

CVE-2021-39890

CVSS 3.1
9.8 critical
EPSS
1%p63
Published
()
Modified
Description

It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 and above.

Vendors
gitlab
Products
gitlab
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.