MEDIUM

CVE-2021-39882

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
5.3

Description

In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.

Summary dbcve.org

Anonymous (unauthenticated) users can access certain GitLab API endpoints using only a user ID, allowing them to retrieve sensitive information about any GitLab user without authentication. This information disclosure affects all versions of GitLab CE/EE.

Mitigation

Upgrade GitLab to the patched version released by the vendor. If immediate patching is not possible, consider restricting network access to the affected endpoints or implementing additional access controls at the proxy/load balancer level.

Weakness (CWE)

CWE-319 Cleartext Transmission

EPSS Score

0.58%
Probability of exploitation in next 30 days
46.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE