cvedb.io
CVE-2021-39881
LOW · CVSS 3.5
EPSS exploitation probability: 0%
Published 2021-10-05T14:15:07.883 · Last modified 2026-06-17T04:04:21.247

Summary

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

Affected products

gitlab — gitlab

Does this affect you?

Add your gear to cvedb and we'll alert you only when gitlab ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.