VulnerabilityModified
CVE-2021-39931
Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.
MEDIUM 4.3EPSS 0.86%
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.86% probability · 56th percentile
- CISA KEV
- Not listed
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39931.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/340445Broken Link
- https://hackerone.com/reports/1318379Permissions Required, Third Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39931.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/340445Broken Link
- https://hackerone.com/reports/1318379Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.