vulnerability
FreeBSD: VID-b299417a-5725-11ec-a587-001b217b3468 (CVE-2021-39936): Gitlab -- Multiple Vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:P/I:N/A:N) | Dec 7, 2021 | Nov 4, 2022 | Dec 10, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Dec 7, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025
Description
Gitlab reports: Group members with developer role can escalate their privilege to maintainer on projects that they import When user registration is limited, external users that aren't developers shouldn't have access to the CI Lint API Collision in access memoization leads to potential elevated privileges on groups and projects Project access token names are returned for unauthenticated requesters Sensitive info disclosure in logs Disclosure of a user's custom project and group templates ReDoS in Maven package version Potential denial of service via the Diff feature Regular Expression Denial of Service via user comments Service desk email accessible by any project member Regular Expression Denial of Service via quick actions IDOR in "external status check" API leaks data about any status check on the instance Default branch name visible in public projects restricting access to the source code repository Deploy token allows access to disabled project Wiki Regular Expression Denial of Service via deploy Slash commands Users can reply to Vulnerability Report discussions despite Only Project Members settings Unauthorised deletion of protected branches Author can approve Merge Request after having access revoked HTML Injection via Swagger UI
Solution
freebsd-upgrade-package-gitlab-ce
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.