First published: Thu Nov 04 2021(Updated: )
An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=8.9.6<14.2.6 | |
GitLab | >=8.9.6<14.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39905 is categorized as a medium severity information disclosure vulnerability.
CVE-2021-39905 allows unauthorized users to view basic information about private groups shared with public projects.
Mitigation for CVE-2021-39905 involves upgrading GitLab to versions later than 14.2.6.
CVE-2021-39905 affects GitLab CE/EE versions from 8.9.6 up to 14.2.6.
Yes, CVE-2021-39905 is a publicly disclosed vulnerability that has been documented in the GitLab repository.