4.3
CVSSv2

CVE-2021-22171

Published: 15/01/2021 Updated: 22/01/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an malicious user to steal a victim's API token if they click on a maliciously crafted link

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

Vendor Advisories

Insufficient validation of authentication parameters in GitLab Pages for GitLab 115+ would allow stealing a user's API access token The issue is mitigated in GitLab version 1372, 1364, and 1356 Note: A way to bypass the fix released in GitLab version 1372, 1364, and 1356 has been found and was subsequently fixed in version 1374, 1 ...