CVE-2021-39899 Information
Jun 07, 2022
cve
Description
In all versions of GitLab CE/EE an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.
CVSS Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39899.json https://gitlab.com/gitlab-org/gitlab/-/issues/339154
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
4.2
Share on: