CVE-2021-39915Resource Exposure in Gitlab

CWE-668Resource Exposure5 documents5 sources
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 49.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateDec 14

Description

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab13.0.014.3.6+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=13.0, <14.3.6, >=14.4, <14.4.4, >=14.5, <14.5.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-v4qw-4358-7wh4: Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 132021-12-14
OSV
CVE-2021-39915: Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 132021-12-13

📋Vendor Advisories

2
GitLab
CVE-2021-39915: Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 be2021-12-13
Debian
CVE-2021-39915: gitlab - Improper access control in the GraphQL API in GitLab CE/EE affecting all version...2021