CVE-2021-39915

MEDIUM

GitLab 13.0-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Unauthenticated Exposure of Project Access Token Names via GraphQL API

Title source: llm
STIX 2.1

Description

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the names of project access tokens on arbitrary projects

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1336059

Scores

CVSS v3 5.3
EPSS 0.0027
EPSS Percentile 50.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-668
Status published
Products (1)
gitlab/gitlab 13.0.0 - 14.3.6 (2 CPE variants)
Published Dec 13, 2021
Tracked Since Feb 18, 2026