CVE-2021-39901: Medium severity gitlab vulnerability
Published Nov 4, 2021
·Updated
In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.
Affected Software
6 affected components
GitLab GitLab>=11.10.0<14.2.6
GitLab GitLab>=11.10.0<14.2.6
GitLab GitLab>=14.3.0<14.3.4
GitLab GitLab>=14.3.0<14.3.4
GitLab GitLab=14.4.0
GitLab GitLab=14.4.0
Event History
Nov 4, 2021
CVE Published
via MITRE·11:09 PM
Data Sourced
via MITRE·11:09 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-39901?
CVE-2021-39901 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2021-39901?
To fix CVE-2021-39901, upgrade your GitLab instance to version 14.4.1 or later.
3
Who is affected by CVE-2021-39901?
CVE-2021-39901 affects all GitLab CE/EE versions from 11.10 to 14.2.6 and 14.3.0 to 14.3.4.
4
What does CVE-2021-39901 allow an attacker to do?
CVE-2021-39901 allows an admin of a group to access the SCIM token for that group through a specific endpoint.
5
Is CVE-2021-39901 being actively exploited?
As of the latest updates, there is no evidence that CVE-2021-39901 is actively being exploited in the wild.