HIGH
CVE-2021-22189
CVSS
7.2
Description
Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.
Summary dbcve.org
GitLab CE/EE versions 13.7 and later contain improper certificate validation for the Fortinet OTP (One-Time Password) integration. This vulnerability allows authentication issues due to the failure to properly validate SSL/TLS certificates when communicating with the Fortinet OTP service, potentially enabling man-in-the-middle attacks on the authentication flow.
Mitigation
Upgrade GitLab to a version where the certificate validation issue is resolved, or implement proper certificate chain validation in the Fortinet OTP integration configuration.
Weakness (CWE)
CWE-295
Improper Certificate Validation
EPSS Score
0.66%
Probability of exploitation in next 30 days
49.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.