CVE Vulnerabilities

CVE-2021-39874

Published: Oct 04, 2021 | Modified: Oct 12, 2021
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git commands.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 11.0.0 (including) 14.1.7 (excluding)
Gitlab Gitlab 14.2 (including) 14.2.5 (excluding)
Gitlab Gitlab 14.3 (including) 14.3.1 (excluding)

References