CVE-2021-39883Incorrect Authorization in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 57.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateMay 24

Description

Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab13.11.014.1.7+2
CVEListV5gitlab/gitlab>=13.11, <14.1.7, >=14.2, <14.2.5, >=14.3, <14.3.1+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-8m2q-q4c8-7569: Improper authorization checks in GitLab EE > 132022-05-24
OSV
CVE-2021-39883: Improper authorization checks in all versions of GitLab EE starting from 132021-10-04

📋Vendor Advisories

2
GitLab
CVE-2021-39883: Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all v2021-10-04
Debian
CVE-2021-39883: gitlab - Improper authorization checks in all versions of GitLab EE starting from 13.11 b...2021