CVE-2021-39884: Medium severity GitLab GitLab vulnerability
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39884?
CVE-2021-39884 has a medium severity level as it allows low privileged users to see private group names associated with a project.
How do I fix CVE-2021-39884?
To fix CVE-2021-39884, upgrade your GitLab installation to version 14.1.8, 14.2.6, or 14.3.2 or later.
Who is affected by CVE-2021-39884?
CVE-2021-39884 affects all users of GitLab EE versions from 8.13.0 up to 14.1.7, as well as certain affected versions within 14.2.x and 14.3.x.
What can attackers do with CVE-2021-39884?
Attackers can exploit CVE-2021-39884 to enumerate the names of private groups that have access to a project, potentially leading to information disclosure.
How can I determine if I am vulnerable to CVE-2021-39884?
Check if your GitLab version falls within the affected ranges specified in CVE-2021-39884 to determine vulnerability.