CVE-2021-39915 — Resource Exposure in Gitlab
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 49.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 13
Latest updateDec 14
Description
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2021-39915: Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 be↗2021-12-13
Debian▶
CVE-2021-39915: gitlab - Improper access control in the GraphQL API in GitLab CE/EE affecting all version...↗2021