CVE-2021-39911
Summary
| CVE | CVE-2021-39911 |
|---|---|
| State | PUBLISHED |
| Assigner | GitLab |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-05 00:15:11 UTC |
| Updated | 2026-06-12 14:34:00 UTC |
| Description | An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Problem Types: NVD-CWE-Other | Exposure of private information ('privacy violation') in GitLab
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | [email protected] | Secondary | 1.7 | LOW | CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N |
| 3.1 | CNA | DECLARED | 1.7 | LOW | CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N |
| 2.0 | [email protected] | Primary | 4 | AV:N/AC:L/Au:S/C:P/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Not Found | af854a3a-2127-422b-91ae-364da2661108 | gitlab.com | Broken Link |
| 2021/CVE-2021-39911.json · master · GitLab.org / cves · GitLab | af854a3a-2127-422b-91ae-364da2661108 | gitlab.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: This vulnerability has been discovered internally by the GitLab team (en)