CVE-2021-39896 — Gitlab vulnerability
5 documents5 sources
Severity
3.8LOWNVD
EPSS
0.2%
top 58.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateMay 24
Description
In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:NExploitability: 1.2 | Impact: 2.5
Affected Packages5 packages
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2021-39896: In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged i↗2021-10-04
Debian▶
CVE-2021-39896: gitlab - In all versions of GitLab CE/EE since version 8.0, when an admin uses the impers...↗2021