CVE-2021-39888

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/10/2021
Last modified:
06/10/2022

Description

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 13.10.0 (including) 14.1.7 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 14.2.0 (including) 14.2.5 (excluding)
cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*