HIGH
CVE-2021-39893
CVSS
7.5
Description
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
Summary dbcve.org
A potential denial-of-service vulnerability in GitLab starting version 9.1 allowed parsing files without proper authorization. This could enable an unauthenticated attacker to trigger excessive resource consumption or access file parsing functionality beyond their intended permissions.
Mitigation
Upgrade GitLab to the latest version containing the security patch for CVE-2021-39893 to remediate the unauthorized file parsing and potential DOS condition.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
1.13%
Probability of exploitation in next 30 days
64.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.