Description
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9382 | Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1. |
References
History
No history.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-03T18:37:18.092Z
Reserved: 2021-01-05T00:00:00.000Z
Link: CVE-2021-22236
No data.
Status : Modified
Published: 2021-08-25T19:15:10.207
Modified: 2024-11-21T05:49:46.087
Link: CVE-2021-22236
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD