CVE-2021-39896

LOW

GitLab CE/EE <8.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

References (2)

Core 2
Core References

Scores

CVSS v3 3.8
EPSS 0.0020
EPSS Percentile 41.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Details

Status published
Products (1)
gitlab/gitlab 8.0.0 - 14.1.7 (2 CPE variants)
Published Oct 04, 2021
Tracked Since Feb 18, 2026