5.3
CVSSv3

CVE-2021-39897

Published: 05/11/2021 Updated: 08/11/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

gitlab gitlab 13.0.0

Vendor Advisories

Improper access control in GitLab CE/EE version 105 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred ...