Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-39897

Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.9%
CVSS Severity
CVSS v3 Score 2.6
CVSS v2 Score 5.0
Products affected by CVE-2021-39897
  • Gitlab » Gitlab » Version: 12.10.0
    cpe:2.3:a:gitlab:gitlab:12.10.0
  • Gitlab » Gitlab » Version: 12.10.1
    cpe:2.3:a:gitlab:gitlab:12.10.1
  • Gitlab » Gitlab » Version: 12.10.2
    cpe:2.3:a:gitlab:gitlab:12.10.2
  • Gitlab » Gitlab » Version: 12.10.3
    cpe:2.3:a:gitlab:gitlab:12.10.3
  • Gitlab » Gitlab » Version: 12.10.4
    cpe:2.3:a:gitlab:gitlab:12.10.4
  • Gitlab » Gitlab » Version: 12.10.5
    cpe:2.3:a:gitlab:gitlab:12.10.5
  • Gitlab » Gitlab » Version: 12.10.6
    cpe:2.3:a:gitlab:gitlab:12.10.6
  • Gitlab » Gitlab » Version: 12.9.0
    cpe:2.3:a:gitlab:gitlab:12.9.0
  • Gitlab » Gitlab » Version: 12.9.1
    cpe:2.3:a:gitlab:gitlab:12.9.1
  • Gitlab » Gitlab » Version: 12.9.2
    cpe:2.3:a:gitlab:gitlab:12.9.2
  • Gitlab » Gitlab » Version: 12.9.3
    cpe:2.3:a:gitlab:gitlab:12.9.3
  • Gitlab » Gitlab » Version: 12.9.4
    cpe:2.3:a:gitlab:gitlab:12.9.4
  • Gitlab » Gitlab » Version: 12.9.5
    cpe:2.3:a:gitlab:gitlab:12.9.5
  • Gitlab » Gitlab » Version: 12.9.6
    cpe:2.3:a:gitlab:gitlab:12.9.6
  • Gitlab » Gitlab » Version: 12.9.7
    cpe:2.3:a:gitlab:gitlab:12.9.7
  • Gitlab » Gitlab » Version: 13.0.0
    cpe:2.3:a:gitlab:gitlab:13.0.0


Contact Us

Shodan ® - All rights reserved