CVE-2021-22236 is a high-severity vulnerability affecting GitLab CE/EE versions since 14.1, where improper handling of OAuth client IDs caused newly generated OAuth tokens to be associated with an incorrect client application. This flaw carries a CVSS score of 8.8, indicating a high potential for impact on confidentiality, integrity, and availability, and can be exploited with low privileges over the network. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.1.0, < 14.1.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 14.1.0, < 14.1.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.