CVE-2021-21411 is a medium-severity authorization bypass vulnerability affecting OAuth2-Proxy versions 7.0.0 when using the GitLab provider with the --gitlab-group flag. The flaw allows any authenticated GitLab user to access applications regardless of their group membership, as the authorization check incorrectly compared the configured groups against themselves. The attack vector is network-based with low complexity, requiring high privileges (authenticated user) to exploit, and results in low confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.1.0CPE matchmatch criteria | cpe:2.3:a:oauth2_proxy_project:oauth2_proxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.