CVE-2021-39937: High severity gitlab vulnerability
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39937?
CVE-2021-39937 has been classified as a medium severity vulnerability.
How do I fix CVE-2021-39937?
To fix CVE-2021-39937, upgrade GitLab to version 14.3.6 or later, or to 14.4.4 or later, or to 14.5.2 or later.
What versions are affected by CVE-2021-39937?
All versions of GitLab CE/EE before 14.3.6 and certain versions of 14.4 and 14.5 are affected by CVE-2021-39937.
What are the potential impacts of CVE-2021-39937?
CVE-2021-39937 could lead to elevated privileges in groups and projects under rare circumstances.
Is CVE-2021-39937 specific to GitLab CE or EE?
CVE-2021-39937 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) versions.