CVE-2021-39914: Medium severity gitlab vulnerability
A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39914?
CVE-2021-39914 is classified as a denial of service vulnerability that can lead to excessive resource usage in affected GitLab versions.
How do I fix CVE-2021-39914?
To fix CVE-2021-39914, upgrade GitLab to version 14.2.6 or later, 14.3.4 or later, or ensure you are using a version higher than 14.4.0.
What versions of GitLab are affected by CVE-2021-39914?
CVE-2021-39914 affects GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3, and 14.4.0.
What happens if I have CVE-2021-39914?
If you have CVE-2021-39914, attackers can exploit the vulnerability by using specially crafted usernames, leading to resource exhaustion.
How can I identify if my GitLab instance is vulnerable to CVE-2021-39914?
You can identify if your GitLab instance is vulnerable to CVE-2021-39914 by checking its version against the affected versions listed.