VDB

CVE-2021-22236

CVE-2021-22236 PUBLISHED CVSS 8.800000190734863 HIGH

Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

EPSS 0.87% · 56.2th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.87%
56.2th percentile

Affected Products

VendorProductVersions
Bitnamigitlab14.1.0
Bitnamigitlab14.1.0

Timeline

  • Jul 1, 2021 CVE Published
  • Aug 26, 2021 EPSS Score
  • Oct 23, 2021 EPSS Score
  • Dec 21, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 17, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 17, 2022 EPSS Score
  • Jun 14, 2022 EPSS Score
  • Aug 12, 2022 EPSS Score
  • Dec 7, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›