CVE-2021-39904: Medium severity GitLab GitLab vulnerability
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39904?
CVE-2021-39904 has a medium severity rating due to improper access control in the GitLab API.
How do I fix CVE-2021-39904?
To fix CVE-2021-39904, upgrade GitLab to version 14.2.6 or later, or to version 14.3.4 or later, or to version 14.4.1 or later.
Which versions of GitLab are affected by CVE-2021-39904?
CVE-2021-39904 affects GitLab CE/EE versions from 13.1 up to but not including 14.2.6, and versions from 14.3 up to but not including 14.3.4 and 14.4.0.
What type of vulnerability is CVE-2021-39904?
CVE-2021-39904 is classified as an Improper Access Control vulnerability.
Who can exploit CVE-2021-39904?
CVE-2021-39904 can be exploited by any Merge Request creator who can resolve discussions and apply suggestions within GitLab.