CVE-2021-22221
Description
An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired
Summary dbcve.org
GitLab versions 12.9.0 through 13.12.2 contain insufficient validation of expired passwords across various operations. The vulnerability allows authenticated users whose passwords have expired to retain limited system access rather than being properly locked out. This stems from missing or inadequate checks in the password expiration logic that should enforce complete account lockdown when a password expires.
Mitigation
Upgrade GitLab to version 13.12.2 or later, or apply the relevant security patch. Organizations unable to upgrade immediately should review user access logs for accounts with expired passwords and consider manually revoking sessions for affected users.