CVE Vulnerabilities

CVE-2021-39875

Published: Oct 05, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab13.6.0 (including)14.1.7 (excluding)
GitlabGitlab14.2.0 (including)14.2.5 (excluding)
GitlabGitlab4.3.0 (including)4.3.0 (including)
GitlabUbuntuesm-apps/xenial*
GitlabUbuntuxenial*

References