CVE Vulnerabilities

CVE-2021-39866

Published: Oct 05, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab13.6.0 (including)14.1.7 (excluding)
GitlabGitlab14.2.0 (including)14.2.5 (excluding)
GitlabGitlab4.3.0 (including)4.3.0 (including)
GitlabUbuntuesm-apps/xenial*
GitlabUbuntuxenial*

References