{"api_version":"1","generated_at":"2026-07-23T13:43:41+00:00","cve":"CVE-2021-39909","urls":{"html":"https://cve.report/CVE-2021-39909","api":"https://cve.report/api/cve/CVE-2021-39909.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-39909","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-39909"},"summary":{"title":"CVE-2021-39909","description":"Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances","state":"PUBLIC","assigner":"cve@gitlab.com","published_at":"2021-11-05 00:15:00","updated_at":"2022-10-06 19:55:00"},"problem_types":["CWE-347"],"metrics":[],"references":[{"url":"https://hackerone.com/reports/1237750","name":"https://hackerone.com/reports/1237750","refsource":"MISC","tags":[],"title":"HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39909.json","name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39909.json","refsource":"CONFIRM","tags":[],"title":"2021/CVE-2021-39909.json · master · GitLab.org / cves · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335191","name":"https://gitlab.com/gitlab-org/gitlab/-/issues/335191","refsource":"MISC","tags":[],"title":"Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-39909","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39909","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Thanks vaib25vicky for reporting this vulnerability through our HackerOne bug bounty program","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"39909","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"39909","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"14.4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-39909","qid":"376040","title":"GitLab Multiple Security Vulnerabilities (gitlab release-14.2.6,14.3.4,14.4.1)"},{"cve":"CVE-2021-39909","qid":"690230","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (33557582-3958-11ec-90ba-001b217b3468)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-39909","ASSIGNER":"cve@gitlab.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"GitLab","product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=11.3, <14.2.6"},{"version_value":">=14.3, <14.3.4"},{"version_value":">=14.4, <14.4.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Unverified ownership in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/gitlab/-/issues/335191","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/335191","refsource":"MISC"},{"name":"https://hackerone.com/reports/1237750","url":"https://hackerone.com/reports/1237750","refsource":"MISC"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39909.json","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39909.json","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances"}]},"impact":{"cvss":{"vectorString":"AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","version":"3.1","baseScore":5.2,"baseSeverity":"MEDIUM"}},"credit":[{"lang":"eng","value":"Thanks vaib25vicky for reporting this vulnerability through our HackerOne bug bounty program"}]},"nvd":{"publishedDate":"2021-11-05 00:15:00","lastModifiedDate":"2022-10-06 19:55:00","problem_types":["CWE-347"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.6,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:enterprise:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"14.2.6","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"14.3.4","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"14.4.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"39909","Ordinal":"215615","Title":"CVE-2021-39909","CVE":"CVE-2021-39909","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"39909","Ordinal":"1","NoteData":"Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances","Type":"Description","Title":null},{"CveYear":"2021","CveId":"39909","Ordinal":"2","NoteData":"2021-11-04","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"39909","Ordinal":"3","NoteData":"2021-11-04","Type":"Other","Title":"Modified"}]}}}