CVE-2021-39895

MEDIUM

GitLab 8.0.0-14.1.7 - Information Disclosure via Imported Pipeline Schedules

Title source: llm
STIX 2.1

Description

In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1272535

Scores

CVSS v3 6.0
EPSS 0.0028
EPSS Percentile 51.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L

Details

Status published
Products (2)
gitlab/gitlab 14.3.0 (2 CPE variants)
gitlab/gitlab 8.0.0 - 14.1.7 (2 CPE variants)
Published Nov 05, 2021
Tracked Since Feb 18, 2026