PT-2021-22757 · Gitlab · Gitlab Ce/Ee+1

Published

2021-11-04

·

Updated

2024-03-06

·

CVE-2021-39911

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.9 through 14.2.5 GitLab CE/EE versions 14.3 through 14.3.3 GitLab CE/EE versions 14.4 through 14.4.0
Description An improper access control flaw exposes the private email address of Issue and Merge Requests assignees to Webhook data consumers. This issue affects all versions of GitLab CE/EE within the specified ranges.
Recommendations For versions 13.9 through 14.2.5, update to version 14.2.6 or later. For versions 14.3 through 14.3.3, update to version 14.3.4 or later. For versions 14.4 through 14.4.0, update to version 14.4.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-GITLAB-2021-39911
CVE-2021-39911

Affected Products

Gitlab
Gitlab Ce/Ee