CVE-2021-39872
EUVD-2021-2622905.10.2021, 13:15
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 14.1.0 ≤ 𝑥 < 14.1.7 |
| gitlab | gitlab | 14.1.0 ≤ 𝑥 < 14.1.7 |
| gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
| gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
| gitlab | gitlab | 4.3.0 |
| gitlab | gitlab | 4.3.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References