CVE-2021-22171
15.01.2021, 16:15
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted linkEnginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 11.5.0 ≤ 𝑥 < 13.5.6 |
gitlab | gitlab | 11.5.0 ≤ 𝑥 < 13.5.6 |
gitlab | gitlab | 13.6.0 ≤ 𝑥 < 13.6.4 |
gitlab | gitlab | 13.6.0 ≤ 𝑥 < 13.6.4 |
gitlab | gitlab | 13.7.0 ≤ 𝑥 < 13.7.2 |
gitlab | gitlab | 13.7.0 ≤ 𝑥 < 13.7.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References