CVE Vulnerabilities

CVE-2021-39884

Published: Oct 05, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 8.13.0 (including) 14.1.7 (excluding)
Gitlab Gitlab 14.2.0 (including) 14.2.5 (excluding)
Gitlab Gitlab 14.3.0 (including) 14.3.1 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

References