First published: Tue Oct 05 2021(Updated: )
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.13.0<14.1.7 | |
GitLab | >=8.13.0<14.1.7 | |
GitLab | >=14.2.0<14.2.5 | |
GitLab | >=14.2.0<14.2.5 | |
GitLab | >=14.3.0<14.3.1 | |
GitLab | >=14.3.0<14.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39884 has a medium severity level as it allows low privileged users to see private group names associated with a project.
To fix CVE-2021-39884, upgrade your GitLab installation to version 14.1.8, 14.2.6, or 14.3.2 or later.
CVE-2021-39884 affects all users of GitLab EE versions from 8.13.0 up to 14.1.7, as well as certain affected versions within 14.2.x and 14.3.x.
Attackers can exploit CVE-2021-39884 to enumerate the names of private groups that have access to a project, potentially leading to information disclosure.
Check if your GitLab version falls within the affected ranges specified in CVE-2021-39884 to determine vulnerability.