mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-26 17:47:58 +02:00
18 lines
739 B
Markdown
18 lines
739 B
Markdown
### [CVE-2021-22213](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22213)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://gitlab.com/gitlab-org/gitlab/-/issues/300308
|
|
|
|
#### Github
|
|
- https://github.com/righel/gitlab-version-nse
|
|
|