First published: Mon Oct 04 2021(Updated: )
Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows subgroup members to see epics from all parent subgroups.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=13.11.0<14.1.7 | |
GitLab | >=14.2.0<14.2.5 | |
GitLab | =14.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39883 is classified as a medium severity vulnerability due to improper authorization checks.
To remediate CVE-2021-39883, upgrade GitLab EE to version 14.1.7 or later, 14.2.5 or later, or 14.3.1 or later.
CVE-2021-39883 affects all versions of GitLab EE starting from 13.11 before 14.1.7, as well as specific versions from 14.2.0 and 14.3.0.
CVE-2021-39883 addresses the issue where subgroup members can improperly view epics from parent subgroups.
There is no official workaround for CVE-2021-39883; upgrading is the recommended solution.