MEDIUM

CVE-2021-39866

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
5.4

Description

A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.

Summary dbcve.org

A business logic error in GitLab 13.6+ allows project access tokens to remain valid after their associated project is deleted. Attackers who previously had project access tokens can continue using them for persistent access even post-deletion.

Mitigation

Audit and revoke all project access tokens associated with deleted projects; review access logs for unauthorized activity using these stale tokens; consider upgrading to patched GitLab versions when available.

EPSS Score

0.98%
Probability of exploitation in next 30 days
60.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE