MEDIUM
CVE-2021-39898
CVSS
5.3
Description
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.
Summary dbcve.org
In all versions of GitLab CE/EE since version 10.6, project export functionality includes external webhook tokens in the exported data. An attacker with access to the exported project file could extract these tokens and use them to interact with the project's webhook endpoints, potentially gaining unauthorized access.
Mitigation
Upgrade to a patched version of GitLab. Additionally, rotate any external webhook tokens that may have been exposed in prior project exports as a precautionary measure.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
1.29%
Probability of exploitation in next 30 days
68.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.