CVE-2021-39943Incorrect Authorization in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 52.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateFeb 11

Description

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

NVDgitlab/gitlab14.1.014.3.6+2
debiandebian/gitlab< gitlab 15.10.8+ds1-2 (sid)
CVEListV5gitlab/gitlab>=14.1.0, <14.3.6, >=14.4.0, <14.4.4, >=14.5.0, <14.5.2+2
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-2hjx-qmr7-gg4r: An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 142022-02-11

📋Vendor Advisories

3
Red Hat
gitlab: An authorization logic error in the External Status Check API in GitLab EE2022-02-10
GitLab
CVE-2021-39943: An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions start2022-02-09
Debian
CVE-2021-39943: gitlab - An authorization logic error in the External Status Check API in GitLab EE affec...2021