CVE-2021-39916
4.3
MEDIUM
CVSS 3.1
EPSS 0.28%
Description
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
How to fix CVE-2021-39916
To remediate CVE-2021-39916, upgrade the affected package to a fixed version below.
- Bitnami/gitlab—upgrade to 14.3.6 or later
Is CVE-2021-39916 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 14.1.0, < 14.3.6, >= 14.4.0, < 14.4.4, >= 14.5.0, < 14.5.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |