MEDIUM
CVE-2021-39875
CVSS
5.3
Description
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.
Summary dbcve.org
In GitLab CE/EE versions 13.6 and later, an API endpoint for public groups and projects exposes pending invitation data without proper authorization checks, allowing any user to view sensitive invitation details (email addresses, names, and other enrollment information) for public groups and projects they should not have access to.
Mitigation
Upgrade to GitLab versions 14.3.2, 14.2.5, or 14.1.6 or later, or apply available security patches. Alternatively, if upgrade is not immediately feasible, restrict access to sensitive group/project membership data through additional access controls.
EPSS Score
1.17%
Probability of exploitation in next 30 days
66th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.