PT-2021-22734 · Gitlab · Gitlab Ce/Ee+1

0Xn3Va

·

Published

2021-10-05

·

Updated

2024-03-06

·

CVE-2021-39888

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab EE versions 13.10 through 14.1.7 GitLab EE versions 14.2 through 14.2.5 GitLab EE versions 14.3 through 14.3.1
Description: A specific API endpoint may reveal details about a private group and other sensitive information inside issue and merge request templates.
Recommendations: For versions 13.10 through 14.1.7, update to version 14.1.7 or later. For versions 14.2 through 14.2.5, update to version 14.2.5 or later. For versions 14.3 through 14.3.1, update to version 14.3.1 or later.

Exploit

Fix

Related Identifiers

BIT-GITLAB-2021-39888
CVE-2021-39888

Affected Products

Gitlab
Gitlab Ce/Ee