CVE-2021-39935
Summary
| CVE | CVE-2021-39935 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-13 16:15:00 UTC |
| Updated | 2021-12-15 17:14:00 UTC |
| Description | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API |
Risk And Classification
EPSS: 0.414340000 probability, percentile 0.973780000 (date 2026-04-01)
CISA KEV: Listed on 2026-02-03; due 2026-02-24; ransomware use Unknown
Problem Types: CWE-918
CISA Known Exploited Vulnerability
| Vendor | GitLab |
|---|---|
| Product | Community and Enterprise Editions |
| Name | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-39935 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Not Found | MISC | gitlab.com | |
| 2021/CVE-2021-39935.json · master · GitLab.org / cves · GitLab | CONFIRM | gitlab.com | |
| HackerOne | MISC | hackerone.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks @minhli for reporting this vulnerability through our HackerOne bug bounty program
Legacy QID Mappings
- 690733 Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (b299417a-5725-11ec-a587-001b217b3468)