vulnerability

Gitlab Gitlab: CVE-2021-22251: Incorrect Authorization

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
2021-08-23
Added
2025-04-22
Modified
2025-05-05

Description

Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

Solution

gitlab-gitlab-cve-2021-22251-solution
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.