HIGH
CVE-2021-39937
CVSS
8.8
Description
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
Summary dbcve.org
A collision vulnerability in GitLab's access memoization logic allows cached access control decisions to be incorrectly shared between different users or contexts, potentially enabling privilege escalation in groups and projects.
Mitigation
Upgrade GitLab to version 14.3.6, 14.4.4, 14.5.2 or later to remediate the access memoization collision that could allow privilege escalation.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
0.75%
Probability of exploitation in next 30 days
53.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.