4
CVSSv2

CVE-2021-39930

Published: 13/12/2021 Updated: 16/12/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an malicious user to access a user's custom project and group templates

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

Vendor Advisories

Missing authorization in GitLab EE versions starting from 124 before 1436, starting from 1440 before 1444, and starting from 1450 before 1452 allowed an attacker to access a user's custom project and group templates ...