CVE-2021-39930 Information
Jun 07, 2022
cve
Description
Missing authorization in GitLab EE versions between 12.4 and 14.3.6 between 14.4.0 and 14.4.4 and between 14.5.0 and 14.5.2 allowed an attacker to access a user’s custom project and group templates
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://hackerone.com/reports/475240 https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39930.json https://gitlab.com/gitlab-org/gitlab/-/issues/26103
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: