5.5

CVE-2021-39896

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 8.0.0 < 14.1.7
Gitlab ≫ GitLab SwEdition enterprise Version >= 8.0.0 < 14.1.7
Gitlab ≫ GitLab SwEdition community Version >= 14.2 < 14.2.5
Gitlab ≫ GitLab SwEdition enterprise Version >= 14.2 < 14.2.5
Gitlab ≫ GitLab SwEdition community Version >= 14.3 < 14.3.1
Gitlab ≫ GitLab SwEdition enterprise Version >= 14.3 < 14.3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.46
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.8 1.2 2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
NIST 5.5 8 4.9
AV:N/AC:L/Au:S/C:P/I:P/A:N
cve@gitlab.com 3.8 1.2 2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39896.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/339362
Broken Link