CVE Vulnerabilities

CVE-2021-39892

Published: Jan 18, 2022 | Modified: Aug 08, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they dont have a maintainer role on and disclose email addresses of those users.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.0 (including) 14.1.7 (excluding)
Gitlab Gitlab 14.2 (including) 14.2.5 (excluding)
Gitlab Gitlab 14.3.0 (including) 14.3.0 (including)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu trusty *
Gitlab Ubuntu xenial *

References