6.5

CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 12.9.0 < 13.10.5
Gitlab ≫ GitLab SwEdition enterprise Version >= 12.9.0 < 13.10.5
Gitlab ≫ GitLab SwEdition community Version >= 13.11.0 < 13.11.5
Gitlab ≫ GitLab SwEdition enterprise Version >= 13.11.0 < 13.11.5
Gitlab ≫ GitLab SwEdition community Version >= 13.12.0 < 13.12.2
Gitlab ≫ GitLab SwEdition enterprise Version >= 13.12.0 < 13.12.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.82% 0.528
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
cve@gitlab.com 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-613 Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22221.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/292006
Broken Link