CVE-2021-39872 log

Source
Severity Medium
Remote Yes
Type Access restriction bypass
Description
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
Group Package Affected Fixed Severity Status Ticket
AVG-2431 gitlab 14.3.0-1 14.3.1-1 High Fixed
References
https://about.gitlab.com/releases/2021/09/30/security-release-gitlab-14-3-1-released/#improper-access-control-for-users-with-expired-password
https://hackerone.com/reports/1285226
https://gitlab.com/gitlab-org/gitlab/-/issues/337954