CVE-2021-39879Missing Authentication for Critical Function in Gitlab

Severity
3.5LOWNVD
EPSS
0.1%
top 68.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateMay 24

Description

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:NExploitability: 2.1 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab7.11.014.1.7
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=7.11.0, <14.1.7
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-32w9-cgpf-p2wf: Missing authentication in all versions of GitLab CE/EE since version 72022-05-24
OSV
CVE-2021-39879: Missing authentication in all versions of GitLab CE/EE since version 72021-10-04

📋Vendor Advisories

2
GitLab
CVE-2021-39879: Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor2021-10-04
Debian
CVE-2021-39879: gitlab - Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allo...2021