CVE-2021-39881
3.5
LOW
CVSS 3.1
EPSS 0.25%
Description
In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.
How to fix CVE-2021-39881
To remediate CVE-2021-39881, upgrade the affected package to a fixed version below.
- Bitnami/gitlab—upgrade to 14.1.7 or later
Is CVE-2021-39881 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 7.7.0, < 14.1.7, >= 14.2.0, < 14.2.5, >= 14.3.0, < 14.3.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |