{"containers":{"cna":{"affected":[{"product":"GitLab","vendor":"GitLab","versions":[{"status":"affected","version":">=12.2, <13.12.9"},{"status":"affected","version":">=14.0, <14.0.7"},{"status":"affected","version":">=14.1, <14.1.2"}]}],"credits":[{"lang":"en","value":"Thanks @ashish_r_padelkar for reporting this vulnerability through our HackerOne bug bounty program"}],"descriptions":[{"lang":"en","value":"Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings"}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"description":"Improper input validation in GitLab","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2021-08-23T19:38:04.000Z","orgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","shortName":"GitLab"},"references":[{"tags":["x_refsource_MISC"],"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004"},{"tags":["x_refsource_MISC"],"url":"https://hackerone.com/reports/679567"},{"tags":["x_refsource_CONFIRM"],"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@gitlab.com","ID":"CVE-2021-22251","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=12.2, <13.12.9"},{"version_value":">=14.0, <14.0.7"},{"version_value":">=14.1, <14.1.2"}]}}]},"vendor_name":"GitLab"}]}},"credit":[{"lang":"eng","value":"Thanks @ashish_r_padelkar for reporting this vulnerability through our HackerOne bug bounty program"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings"}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper input validation in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004","refsource":"MISC","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004"},{"name":"https://hackerone.com/reports/679567","refsource":"MISC","url":"https://hackerone.com/reports/679567"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json","refsource":"CONFIRM","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T18:37:18.163Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/14004"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://hackerone.com/reports/679567"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json"}]}]},"cveMetadata":{"assignerOrgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","assignerShortName":"GitLab","cveId":"CVE-2021-22251","datePublished":"2021-08-23T19:38:04.000Z","dateReserved":"2021-01-05T00:00:00.000Z","dateUpdated":"2024-08-03T18:37:18.163Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}