MEDIUM

CVE-2021-22213

Gitlab GitLab 2021-06-08 CVSS v3.1
CVSS
6.5

Description

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

Summary dbcve.org

This is a cross-site leak (XS-Leak) vulnerability in GitLab's OAuth authorization flow. An attacker can exploit timing differences or browser-specific behavior in Safari to extract the OAuth access token from the authorization callback response by tricking authenticated users into visiting a malicious webpage.

Mitigation

Users should avoid clicking untrusted links while authenticated to GitLab. GitLab should implement POST-based OAuth callbacks or token binding to prevent token leakage via XS-Leak attacks.

EPSS Score

1.67%
Probability of exploitation in next 30 days
75.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE