CVE-2021-39886
CVE-2021-39886
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2.6EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Oct 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Affected products
GitLab · GitLabWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →