• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-863

CVE-2021-22236

February 23, 2023 by

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

CVE-2021-22239

February 23, 2023 by

An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.

CVE-2021-22240

February 23, 2023 by

Improper access control in GitLab EE versions 13.11.6, 13.12.6, and 14.0.2 allows users to be created via single sign on despite user cap being enabled

CVE-2021-22243

February 23, 2023 by

Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.

CVE-2021-22247

February 23, 2023 by

Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

CVE-2021-22251

February 23, 2023 by

Improper validation of invited users’ email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 101
  • Go to page 102
  • Go to page 103
  • Go to page 104
  • Go to page 105
  • Interim pages omitted …
  • Go to page 192
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE