HIGH

CVE-2021-39893

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
7.5

Description

A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.

Summary dbcve.org

A potential denial-of-service vulnerability in GitLab starting version 9.1 allowed parsing files without proper authorization. This could enable an unauthenticated attacker to trigger excessive resource consumption or access file parsing functionality beyond their intended permissions.

Mitigation

Upgrade GitLab to the latest version containing the security patch for CVE-2021-39893 to remediate the unauthorized file parsing and potential DOS condition.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

1.13%
Probability of exploitation in next 30 days
64.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE