CVE-2021-39911 Vulnerability Details

  /     /     /  

CVE-2021-39911 Metadata Quick Info

CVE Published: 04/11/2021 | CVE Updated: 04/08/2024 | CVE Year: 2021
Source: GitLab | Vendor: GitLab | Product: GitLab
Status : PUBLISHED

CVE-2021-39911 Description

An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers

Metrics

CVSS Version: 3.1 | Base Score: 1.7 LOW
Vector: CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* PHYSICAL
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Exposure of private information ( privacy violation ) in GitLab
Source: GitLab

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).