MEDIUM

CVE-2021-22221

Gitlab GitLab 2021-06-08 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

Summary dbcve.org

GitLab versions 12.9.0 through 13.12.2 contain insufficient validation of expired passwords across various operations. The vulnerability allows authenticated users whose passwords have expired to retain limited system access rather than being properly locked out. This stems from missing or inadequate checks in the password expiration logic that should enforce complete account lockdown when a password expires.

Mitigation

Upgrade GitLab to version 13.12.2 or later, or apply the relevant security patch. Organizations unable to upgrade immediately should review user access logs for accounts with expired passwords and consider manually revoking sessions for affected users.

Weakness (CWE)

CWE-613

EPSS Score

0.82%
Probability of exploitation in next 30 days
55.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE