CVE-2021-39908: Code Injection
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39908?
CVE-2021-39908 has been classified as a medium severity vulnerability.
How do I fix CVE-2021-39908?
To fix CVE-2021-39908, update GitLab to the latest version that is not affected by this vulnerability.
Which versions are affected by CVE-2021-39908?
CVE-2021-39908 affects all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6 and specific ranges from 14.3 and 14.4.
What is the impact of CVE-2021-39908?
CVE-2021-39908 allows attackers to commit malicious code without detection in merge requests or source code.
Is there a workaround for CVE-2021-39908?
The best approach for CVE-2021-39908 is to upgrade to a patched version of GitLab, as no effective workaround is available.