MEDIUM
CVE-2021-39897
CVSS
5.3
Description
Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred
Summary dbcve.org
In GitLab CE/EE versions 10.5 and above, improper access control allows subgroup members who inherited project access from a parent group to retain that access even after the subgroup is transferred to a different namespace. This occurs because the inherited access permissions are not properly revoked during the subgroup transfer operation.
Mitigation
Upgrade GitLab to the latest patched version and audit group/project memberships after any subgroup transfers to ensure access is correctly scoped.
Weakness (CWE)
CWE-281
EPSS Score
1.03%
Probability of exploitation in next 30 days
62.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.