MEDIUM

CVE-2021-39941

Gitlab GitLab 2021-12-13 CVSS v3.1
CVSS
5.3

Description

An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

Summary dbcve.org

In affected GitLab versions, the default branch name was disclosed to non-project members even when project repository access was restricted to members only. This occurred because the system exposed the default branch name in certain API responses or UI elements accessible to unauthenticated or non-member users.

Mitigation

Upgrade GitLab to version 14.3.7, 14.4.5, or 14.5.3 or later. Alternatively, ensure repository access restrictions are properly configured and consider network-level access controls until patching is feasible.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

1.18%
Probability of exploitation in next 30 days
66.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE