CVE-2021-39911
Last modified
CVE-2021-39911 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 13.9.0, < 14.2.6 |
| Gitlab | Gitlab | >= 14.3.0, < 14.3.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-39911?
How severe is CVE-2021-39911?
How do I fix CVE-2021-39911?
Are you affected by CVE-2021-39911?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
