CVE-2021-39888
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info…
Does this matter?
Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.
Description
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/336446Broken Link, Exploit, Issue Tracking, Vendor Advisory
- https://hackerone.com/reports/1255128Permissions Required
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/336446Broken Link, Exploit, Issue Tracking, Vendor Advisory
- https://hackerone.com/reports/1255128Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.