CVE-2021-39903: Medium severity gitlab vulnerability
In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39903?
CVE-2021-39903 is considered a high severity vulnerability due to its potential to change project visibility settings by privileged users.
How do I fix CVE-2021-39903?
To mitigate CVE-2021-39903, upgrade GitLab to version 14.4.0 or later, or apply any available patches.
What versions of GitLab are affected by CVE-2021-39903?
CVE-2021-39903 affects all GitLab CE/EE versions from 13.0.0 up to but not including 14.2.6 as well as specific versions between 14.3.0 and 14.3.4.
What protections does GitLab provide against CVE-2021-39903?
GitLab provides the ability for instance administrators to restrict visibility settings, but this vulnerability allows privileged users to bypass those restrictions.
Who is impacted by CVE-2021-39903?
Privileged users on GitLab instances configured with restricted project visibility are directly impacted by CVE-2021-39903.