First published: Mon Dec 13 2021(Updated: )
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | <14.3.6 | |
GitLab | <14.3.6 | |
GitLab | >=14.4.0<14.4.4 | |
GitLab | >=14.4.0<14.4.4 | |
GitLab | >=14.5.0<14.5.2 | |
GitLab | >=14.5.0<14.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39937 has been classified as a medium severity vulnerability.
To fix CVE-2021-39937, upgrade GitLab to version 14.3.6 or later, or to 14.4.4 or later, or to 14.5.2 or later.
All versions of GitLab CE/EE before 14.3.6 and certain versions of 14.4 and 14.5 are affected by CVE-2021-39937.
CVE-2021-39937 could lead to elevated privileges in groups and projects under rare circumstances.
CVE-2021-39937 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) versions.