5.3

CVE-2021-39897

Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 12.9.0 < 12.9.8
Gitlab ≫ GitLab SwEdition enterprise Version >= 12.9.0 < 12.9.8
Gitlab ≫ GitLab SwEdition community Version >= 12.10.0 < 12.10.7
Gitlab ≫ GitLab SwEdition enterprise Version >= 12.10.0 < 12.10.7
Gitlab ≫ GitLab Version 13.0.0 SwEdition community
Gitlab ≫ GitLab Version 13.0.0 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1% 0.585
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
cve@gitlab.com 2.6 1.2 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
CWE-281 Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39897.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/341017
Broken Link
https://hackerone.com/reports/1330806
Third Party Advisory
Permissions Required