CVE Vulnerabilities

CVE-2021-39874

Published: Oct 04, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 11.0.0 (including) 14.1.7 (excluding)
Gitlab Gitlab 14.2 (including) 14.2.5 (excluding)
Gitlab Gitlab 14.3 (including) 14.3.1 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References