MEDIUM

CVE-2021-39898

Gitlab GitLab 2021-11-05 CVSS v3.1
CVSS
5.3

Description

In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.

Summary dbcve.org

In all versions of GitLab CE/EE since version 10.6, project export functionality includes external webhook tokens in the exported data. An attacker with access to the exported project file could extract these tokens and use them to interact with the project's webhook endpoints, potentially gaining unauthorized access.

Mitigation

Upgrade to a patched version of GitLab. Additionally, rotate any external webhook tokens that may have been exposed in prior project exports as a precautionary measure.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

1.29%
Probability of exploitation in next 30 days
68.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE