CVE-2021-22251
Summary
| CVE | CVE-2021-22251 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-23 20:15:00 UTC |
| Updated | 2021-08-28 01:25:00 UTC |
| Description | Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2021/CVE-2021-22251.json · master · GitLab.org / cves · GitLab | CONFIRM | gitlab.com | |
| HackerOne | MISC | hackerone.com | |
| ESCALATED: Projects are allowed to add members with different domain email address despite restricting in group settings (#14004) · Issues · GitLab.org / GitLab · GitLab | MISC | gitlab.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks @ashish_r_padelkar for reporting this vulnerability through our HackerOne bug bounty program
There are currently no legacy QID mappings associated with this CVE.