MEDIUM
CVE-2021-39882
CVSS
5.3
Description
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
Summary dbcve.org
Anonymous (unauthenticated) users can access certain GitLab API endpoints using only a user ID, allowing them to retrieve sensitive information about any GitLab user without authentication. This information disclosure affects all versions of GitLab CE/EE.
Mitigation
Upgrade GitLab to the patched version released by the vendor. If immediate patching is not possible, consider restricting network access to the affected endpoints or implementing additional access controls at the proxy/load balancer level.
Weakness (CWE)
CWE-319
Cleartext Transmission
EPSS Score
0.58%
Probability of exploitation in next 30 days
46.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.