CVE-2021-39915: Medium severity gitlab vulnerability
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39915?
CVE-2021-39915 has been rated as a medium severity vulnerability due to improper access control allowing unauthorized access to project access token names.
How do I fix CVE-2021-39915?
To fix CVE-2021-39915, upgrade your GitLab installation to version 14.3.6 or above, 14.4.4 or above, or 14.5.2 or above.
What versions of GitLab are affected by CVE-2021-39915?
CVE-2021-39915 affects GitLab CE/EE versions starting from 13.0 before 14.3.6, 14.4 before 14.4.4, and 14.5 before 14.5.2.
What are the potential impacts of CVE-2021-39915?
The potential impact of CVE-2021-39915 includes exposure of project access token names, which could facilitate further attacks.
Is CVE-2021-39915 being exploited in the wild?
There have been no confirmed reports of CVE-2021-39915 being actively exploited in the wild, but it is advisable to apply patches promptly.