CVE-2021-39931

LOW

GitLab CE/EE <14.3.6-14.5.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Under specific condition an unauthorised project member was allowed to delete a protected branches due to a business logic error.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/1318379

Scores

CVSS v3 3.1
EPSS 0.0025
EPSS Percentile 48.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (1)
gitlab/gitlab 8.11.0 - 14.3.6 (2 CPE variants)
Published Dec 13, 2021
Tracked Since Feb 18, 2026