CVE Vulnerabilities

CVE-2021-39875

Published: Oct 05, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 13.6.0 (including) 14.1.7 (excluding)
Gitlab Gitlab 14.2.0 (including) 14.2.5 (excluding)
Gitlab Gitlab 4.3.0 (including) 4.3.0 (including)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References