CVE-2021-39915
MEDIUMGitlab < 14.3.6 - Exposure to Wrong Actor
Title source: ruleDescription
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects
Scores
CVSS v3
5.3
EPSS
0.0027
EPSS Percentile
50.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-668
Status
published
Affected Products (2)
gitlab/gitlab
< 14.3.6
gitlab/gitlab
< 14.3.6
Timeline
Published
Dec 13, 2021
Tracked Since
Feb 18, 2026