#VU57048 Security features bypass in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2021-39881
Published: October 5, 2021
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the application may let a malicious user create an OAuth client application with arbitrary scope names. A remote authenticated attacker can trick a victim to authorize the malicious client application using the spoofed scope name and description.