CVE-2021-39902: Medium severity gitlab vulnerability
Published Nov 4, 2021
·Updated
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.
Affected Software
6 affected components
GitLab GitLab>=13.4.0<14.2.6
GitLab GitLab>=13.4.0<14.2.6
GitLab GitLab>=14.3.0<14.3.4
GitLab GitLab>=14.3.0<14.3.4
GitLab GitLab=14.4.0
GitLab GitLab=14.4.0
Event History
Nov 4, 2021
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-39902?
CVE-2021-39902 is classified as a critical vulnerability due to incorrect authorization allowing unauthorized modifications to incident severities.
2
How do I fix CVE-2021-39902?
To fix CVE-2021-39902, update GitLab to version 14.4.0 or later, or to versions 13.4.6 or 14.2.6 if using earlier versions.
3
Who is affected by CVE-2021-39902?
Users with guest membership in GitLab projects utilizing versions 13.4.0 through 14.3.4 are affected by CVE-2021-39902.
4
What does CVE-2021-39902 allow an attacker to do?
CVE-2021-39902 allows an attacker with guest access to change the severity level of incidents within a GitLab project.
5
When was CVE-2021-39902 discovered?
CVE-2021-39902 was discovered and reported in 2021, affecting multiple versions of GitLab.