MEDIUM

CVE-2021-39897

Gitlab GitLab 2021-11-05 CVSS v3.1
CVSS
5.3

Description

Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred

Summary dbcve.org

In GitLab CE/EE versions 10.5 and above, improper access control allows subgroup members who inherited project access from a parent group to retain that access even after the subgroup is transferred to a different namespace. This occurs because the inherited access permissions are not properly revoked during the subgroup transfer operation.

Mitigation

Upgrade GitLab to the latest patched version and audit group/project memberships after any subgroup transfers to ensure access is correctly scoped.

Weakness (CWE)

CWE-281

EPSS Score

1.03%
Probability of exploitation in next 30 days
62.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE