CVE-2021-39909 — Improper Verification of Cryptographic Signature in Gitlab
Severity
5.3MEDIUMNVD
EPSS
0.0%
top 84.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 5
Latest updateMay 24
Description
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-xxx4-cx36-38r5: Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11↗2022-05-24
📋Vendor Advisories
2GitLab▶
CVE-2021-39909: Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions sta↗2021-11-05
Debian▶
CVE-2021-39909: gitlab - Lack of email address ownership verification in the CODEOWNERS feature in all ve...↗2021