4
CVSSv2

CVE-2021-39892

Published: 18/01/2022 Updated: 08/08/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

gitlab gitlab 14.3.0

Vendor Advisories

In all versions of GitLab CE/EE since version 120, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users ...