Medium severity4.3NVD Advisory· Published Aug 23, 2021· Updated Jun 17, 2026
CVE-2021-22251
CVE-2021-22251
Description
Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.2.0,<13.12.9
- (no CPE)range: >=12.2, <13.12.9
- Range: since 12.2
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/gitlab/-/issues/14004nvdExploitIssue TrackingVendor Advisory
- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.jsonnvdVendor Advisory
- hackerone.com/reports/679567nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.