Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-39872

In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2021-39872
  • Gitlab » Gitlab » Version: 14.1.0
    cpe:2.3:a:gitlab:gitlab:14.1.0
  • Gitlab » Gitlab » Version: 14.1.1
    cpe:2.3:a:gitlab:gitlab:14.1.1
  • Gitlab » Gitlab » Version: 14.1.2
    cpe:2.3:a:gitlab:gitlab:14.1.2
  • Gitlab » Gitlab » Version: 14.1.3
    cpe:2.3:a:gitlab:gitlab:14.1.3
  • Gitlab » Gitlab » Version: 14.1.4
    cpe:2.3:a:gitlab:gitlab:14.1.4
  • Gitlab » Gitlab » Version: 14.1.5
    cpe:2.3:a:gitlab:gitlab:14.1.5
  • Gitlab » Gitlab » Version: 14.1.6
    cpe:2.3:a:gitlab:gitlab:14.1.6
  • Gitlab » Gitlab » Version: 14.2.0
    cpe:2.3:a:gitlab:gitlab:14.2.0
  • Gitlab » Gitlab » Version: 14.2.1
    cpe:2.3:a:gitlab:gitlab:14.2.1
  • Gitlab » Gitlab » Version: 14.2.2
    cpe:2.3:a:gitlab:gitlab:14.2.2
  • Gitlab » Gitlab » Version: 14.2.3
    cpe:2.3:a:gitlab:gitlab:14.2.3
  • Gitlab » Gitlab » Version: 14.2.4
    cpe:2.3:a:gitlab:gitlab:14.2.4
  • Gitlab » Gitlab » Version: 4.3.0
    cpe:2.3:a:gitlab:gitlab:4.3.0


Contact Us

Shodan ® - All rights reserved