In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2021-10-05T12:34:28

Updated: 2021-10-05T12:34:28

Reserved: 2021-08-23T00:00:00


Link: CVE-2021-39872

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-05T13:15:08.090

Modified: 2021-10-12T18:24:40.737


Link: CVE-2021-39872

JSON object: View

cve-icon Redhat Information

No data.

CWE