PT-2021-22769 · Gitlab · Gitlab Ce/Ee+1

Ngalog

·

Published

2021-12-13

·

Updated

2024-03-06

·

CVE-2021-39930

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 12.4 through 14.3.6 GitLab EE versions 14.4.0 through 14.4.4 GitLab EE versions 14.5.0 through 14.5.2
Description The issue concerns missing authorization, allowing an attacker to access a user's custom project and group templates.
Recommendations For GitLab EE versions 12.4 through 14.3.6, update to a version outside of this range to resolve the issue. For GitLab EE versions 14.4.0 through 14.4.4, update to a version outside of this range to resolve the issue. For GitLab EE versions 14.5.0 through 14.5.2, update to a version outside of this range to resolve the issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39930
CVE-2021-39930

Affected Products

Gitlab
Gitlab Ce/Ee