HIGH

CVE-2021-39944

Gitlab GitLab 2021-12-13 CVSS v3.1
CVSS
7.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to elevate their privilege to a maintainer on projects they import

Summary dbcve.org

A permissions validation flaw in GitLab CE/EE allowed group members with developer roles to import projects and automatically gain maintainer privileges on those imported projects, enabling privilege escalation.

Mitigation

Upgrade GitLab to version 14.3.6, 14.4.4, 14.5.2 or later to patch the permission validation vulnerability.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

0.92%
Probability of exploitation in next 30 days
58.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE