CVE-2021-39903

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/11/2021
Last modified:
12/07/2022

Description

In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 13.0.0 (including) 14.2.6 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 13.0.0 (including) 14.2.6 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 14.3.0 (including) 14.3.4 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 14.3.0 (including) 14.3.4 (excluding)
cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:enterprise:*:*:*