MEDIUM
CVE-2021-39866
CVSS
5.4
Description
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
Summary dbcve.org
A business logic error in GitLab 13.6+ allows project access tokens to remain valid after their associated project is deleted. Attackers who previously had project access tokens can continue using them for persistent access even post-deletion.
Mitigation
Audit and revoke all project access tokens associated with deleted projects; review access logs for unauthorized activity using these stale tokens; consider upgrading to patched GitLab versions when available.
EPSS Score
0.98%
Probability of exploitation in next 30 days
60.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.