
Cloud Vulnerability DB
A community-led vulnerabilities database
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link. The vulnerability was discovered in January 2021 and assigned identifier CVE-2021-22171. This security issue affects GitLab installations from version 11.5 onwards (GitLab Release, NVD).
The vulnerability stems from improper validation of authentication parameters in the GitLab Pages authentication flow. The issue has a CVSS v3.1 base score of 6.5 (Medium), with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. The attack requires network access and user interaction, but no privileges, and can result in high confidentiality impact (Ubuntu CVE).
If successfully exploited, the vulnerability allows attackers to steal a victim's API access token through GitLab Pages. This could lead to unauthorized access to the victim's GitLab resources and potentially expose sensitive information (GitLab Release).
The vulnerability requires the attacker to craft a malicious link and convince a victim to click on it. The attack vector is network-based with low attack complexity, requiring no privileges but necessitating user interaction (Ubuntu CVE).
The vulnerability was patched in GitLab versions 13.7.2, 13.6.4, and 13.5.6. Organizations are strongly recommended to upgrade their GitLab installations to one of these versions or later to mitigate the vulnerability (GitLab Release).
The vulnerability was initially reported through GitLab's HackerOne bug bounty program by researcher @ngalog. GitLab addressed the issue promptly by releasing security patches and assigning it a CVE identifier (GitLab Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."