CVE-2021-39937
8.8
HIGH
CVSS 3.1
EPSS 0.15%
Description
A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances
How to fix CVE-2021-39937
To remediate CVE-2021-39937, upgrade the affected package to a fixed version below.
- Bitnami/gitlab—upgrade to 14.3.6 or later
Is CVE-2021-39937 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 14.3.6, >= 14.4.0, < 14.4.4, >= 14.5.0, < 14.5.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |