CVE-2021-39941
Description
An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members
Summary dbcve.org
In affected GitLab versions, the default branch name was disclosed to non-project members even when project repository access was restricted to members only. This occurred because the system exposed the default branch name in certain API responses or UI elements accessible to unauthenticated or non-member users.
Mitigation
Upgrade GitLab to version 14.3.7, 14.4.5, or 14.5.3 or later. Alternatively, ensure repository access restrictions are properly configured and consider network-level access controls until patching is feasible.