CVE-2021-39870: Medium severity GitLab GitLab vulnerability
Published Oct 5, 2021
·Updated
In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enabled is bypassed by an attacker making a crafted API call.
Affected Software
6 affected components
GitLab GitLab>=11.11.0<14.1.7
GitLab GitLab>=11.11.0<14.1.7
GitLab GitLab>=14.2.0<14.2.5
GitLab GitLab>=14.2.0<14.2.5
GitLab GitLab>=14.3.0<14.3.1
GitLab GitLab>=14.3.0<14.3.1
Event History
Oct 5, 2021
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-39870?
CVE-2021-39870 is rated as a medium-severity vulnerability due to the potential for unauthorized access to repository imports.
2
How do I fix CVE-2021-39870?
To mitigate CVE-2021-39870, update GitLab to a patched version beyond 14.1.7, 14.2.5, or 14.3.1.
3
What environments are affected by CVE-2021-39870?
CVE-2021-39870 affects all versions of GitLab CE/EE from 11.11.0 up to 14.3.1.
4
Is CVE-2021-39870 being actively exploited?
At this time, there are no public reports of active exploitation specifically targeting CVE-2021-39870.
5
What kind of attack does CVE-2021-39870 facilitate?
CVE-2021-39870 allows attackers to bypass the Repo by URL import restriction via crafted API calls.