HIGH

CVE-2021-22189

Gitlab GitLab 2021-03-04 CVSS v3.1
CVSS
7.2

Description

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

Summary dbcve.org

GitLab CE/EE versions 13.7 and later contain improper certificate validation for the Fortinet OTP (One-Time Password) integration. This vulnerability allows authentication issues due to the failure to properly validate SSL/TLS certificates when communicating with the Fortinet OTP service, potentially enabling man-in-the-middle attacks on the authentication flow.

Mitigation

Upgrade GitLab to a version where the certificate validation issue is resolved, or implement proper certificate chain validation in the Fortinet OTP integration configuration.

Weakness (CWE)

CWE-295 Improper Certificate Validation

EPSS Score

0.66%
Probability of exploitation in next 30 days
49.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE