CVE-2021-39940: Medium severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39940?
CVE-2021-39940 has been classified as a medium severity vulnerability.
How do I fix CVE-2021-39940?
To mitigate CVE-2021-39940, upgrade GitLab to version 14.3.6 or later, 14.4.4 or later, or 14.5.2 or later.
What versions of GitLab are affected by CVE-2021-39940?
CVE-2021-39940 affects GitLab CE/EE versions between 13.2.0 and 14.3.6, 14.4.0 and 14.4.4, and 14.5.0 and 14.5.2.
What type of attack is possible with CVE-2021-39940?
CVE-2021-39940 allows for a regular expression denial of service attack.
Is CVE-2021-39940 present in all GitLab versions?
No, CVE-2021-39940 is only present in specific versions of GitLab prior to the patched releases.