PT-2021-22751 · Gitlab · Gitlab Ce/Ee+1

Jimenoon

·

Published

2021-11-04

·

Updated

2024-03-06

·

CVE-2021-39904

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.1 through 14.2.6 GitLab CE/EE versions 14.3 through 14.3.4 GitLab CE/EE versions 14.4 through 14.4.1
Description The issue is related to an Improper Access Control vulnerability in the GraphQL API. This vulnerability allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request.
Recommendations For GitLab CE/EE versions 13.1 through 14.2.6, update to version 14.2.6 or later. For GitLab CE/EE versions 14.3 through 14.3.4, update to version 14.3.4 or later. For GitLab CE/EE versions 14.4 through 14.4.1, update to version 14.4.1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39904
CVE-2021-39904

Affected Products

Gitlab
Gitlab Ce/Ee