CVE-2021-39888

In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 06:20

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.json - Vendor Advisory () https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.json - Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/336446 - Broken Link, Exploit, Issue Tracking, Vendor Advisory () https://gitlab.com/gitlab-org/gitlab/-/issues/336446 - Broken Link, Exploit, Issue Tracking, Vendor Advisory
References () https://hackerone.com/reports/1255128 - Permissions Required () https://hackerone.com/reports/1255128 - Permissions Required

13 May 2022, 14:15

Type Values Removed Values Added
Summary In all versions of GitLab EE since version 13.10, a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates. In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.

12 Oct 2021, 16:39

Type Values Removed Values Added
References (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/336446 - (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/336446 - Broken Link
References (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.json - (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39888.json - Vendor Advisory
References (MISC) https://hackerone.com/reports/1255128 - (MISC) https://hackerone.com/reports/1255128 - Permissions Required
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
CWE CWE-200

05 Oct 2021, 13:26

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-05 13:15

Updated : 2024-11-21 06:20


NVD link : CVE-2021-39888

Mitre link : CVE-2021-39888

CVE.ORG link : CVE-2021-39888


JSON object : View

Products Affected

gitlab

  • gitlab