HIGH

CVE-2021-39937

Gitlab GitLab 2021-12-13 CVSS v3.1
CVSS
8.8

Description

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

Summary dbcve.org

A collision vulnerability in GitLab's access memoization logic allows cached access control decisions to be incorrectly shared between different users or contexts, potentially enabling privilege escalation in groups and projects.

Mitigation

Upgrade GitLab to version 14.3.6, 14.4.4, 14.5.2 or later to remediate the access memoization collision that could allow privilege escalation.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

0.75%
Probability of exploitation in next 30 days
53.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE