CVE Vulnerabilities

CVE-2021-39901

Published: Nov 05, 2021 | Modified: Nov 08, 2021
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 11.10.0 (including) 14.2.6 (excluding)
Gitlab Gitlab 14.3.0 (including) 14.3.4 (excluding)
Gitlab Gitlab 14.4.0 (including) 14.4.0 (including)
Gitlab Ubuntu esm-apps/xenial *

References