CVE-2021-39888

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*

History

06 Oct 2022, 20:04

Type Values Removed Values Added
References (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/336446 - Broken Link (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/336446 - Broken Link, Exploit, Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*
CWE CWE-200

13 May 2022, 14:15

Type Values Removed Values Added
Summary In all versions of GitLab EE since version 13.10, a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates. In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

12 Oct 2021, 16:39

Type Values Removed Values Added
CWE CWE-200
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
References (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.json - (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.json - Vendor Advisory
References (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/336446 - (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/336446 - Broken Link
References (MISC) https://hackerone.com/reports/1255128 - (MISC) https://hackerone.com/reports/1255128 - Permissions Required

05 Oct 2021, 13:26

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-05 13:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-39888

Mitre link : CVE-2021-39888

CVE.ORG link : CVE-2021-39888


JSON object : View

Products Affected

gitlab

  • gitlab