MEDIUM

CVE-2021-39875

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
5.3

Description

In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.

Summary dbcve.org

In GitLab CE/EE versions 13.6 and later, an API endpoint for public groups and projects exposes pending invitation data without proper authorization checks, allowing any user to view sensitive invitation details (email addresses, names, and other enrollment information) for public groups and projects they should not have access to.

Mitigation

Upgrade to GitLab versions 14.3.2, 14.2.5, or 14.1.6 or later, or apply available security patches. Alternatively, if upgrade is not immediately feasible, restrict access to sensitive group/project membership data through additional access controls.

EPSS Score

1.17%
Probability of exploitation in next 30 days
66th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE