CVE-2021-39907: Medium severity gitlab vulnerability
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from certain images resulted in high CPU usage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39907?
CVE-2021-39907 has a moderate severity rating due to its potential Denial of Service impact.
How do I fix CVE-2021-39907?
To mitigate CVE-2021-39907, upgrade GitLab to version 14.2.6 or later for versions 13.7 to 14.2, and to version 14.4.1 or later for versions 14.3.
What versions of GitLab are affected by CVE-2021-39907?
CVE-2021-39907 affects GitLab CE/EE starting from version 13.7 to versions prior to 14.2.6 and also from 14.3.0 to prior to 14.4.1.
What type of vulnerability is CVE-2021-39907?
CVE-2021-39907 is identified as a Denial of Service (DoS) vulnerability due to high CPU usage from processing certain images.
Can CVE-2021-39907 impact the performance of my GitLab instance?
Yes, CVE-2021-39907 can significantly impact the performance of your GitLab instance by causing high CPU usage.