{"api_version":"1","generated_at":"2026-07-23T14:37:21+00:00","cve":"CVE-2021-22251","urls":{"html":"https://cve.report/CVE-2021-22251","api":"https://cve.report/api/cve/CVE-2021-22251.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-22251","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-22251"},"summary":{"title":"CVE-2021-22251","description":"Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings","state":"PUBLIC","assigner":"cve@gitlab.com","published_at":"2021-08-23 20:15:00","updated_at":"2021-08-28 01:25:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json","name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json","refsource":"CONFIRM","tags":[],"title":"2021/CVE-2021-22251.json · master · GitLab.org / cves · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://hackerone.com/reports/679567","name":"https://hackerone.com/reports/679567","refsource":"MISC","tags":[],"title":"HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004","name":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004","refsource":"MISC","tags":[],"title":"ESCALATED: Projects are allowed to add members with different domain email address despite restricting in group settings (#14004) · Issues · GitLab.org / GitLab · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-22251","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22251","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Thanks @ashish_r_padelkar for reporting this vulnerability through our HackerOne bug bounty program","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"22251","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-22251","ASSIGNER":"cve@gitlab.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"GitLab","product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=12.2, <13.12.9"},{"version_value":">=14.0, <14.0.7"},{"version_value":">=14.1, <14.1.2"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper input validation in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004","refsource":"MISC"},{"name":"https://hackerone.com/reports/679567","url":"https://hackerone.com/reports/679567","refsource":"MISC"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings"}]},"impact":{"cvss":{"vectorString":"AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","version":"3.1","baseScore":4.2,"baseSeverity":"MEDIUM"}},"credit":[{"lang":"eng","value":"Thanks @ashish_r_padelkar for reporting this vulnerability through our HackerOne bug bounty program"}]},"nvd":{"publishedDate":"2021-08-23 20:15:00","lastModifiedDate":"2021-08-28 01:25:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.1.0","versionEndExcluding":"14.1.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.0.7","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.2.0","versionEndExcluding":"13.12.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"22251","Ordinal":"196952","Title":"CVE-2021-22251","CVE":"CVE-2021-22251","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"22251","Ordinal":"1","NoteData":"Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings","Type":"Description","Title":null},{"CveYear":"2021","CveId":"22251","Ordinal":"2","NoteData":"2021-08-23","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"22251","Ordinal":"3","NoteData":"2021-08-23","Type":"Other","Title":"Modified"}]}}}