{"api_version":"1","generated_at":"2026-07-24T23:44:51+00:00","cve":"CVE-2021-39911","urls":{"html":"https://cve.report/CVE-2021-39911","api":"https://cve.report/api/cve/CVE-2021-39911.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-39911","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-39911"},"summary":{"title":"CVE-2021-39911","description":"An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers","state":"PUBLISHED","assigner":"GitLab","published_at":"2021-11-05 00:15:11","updated_at":"2026-06-12 14:34:00"},"problem_types":["NVD-CWE-Other","Exposure of private information ('privacy violation') in GitLab"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"cve@gitlab.com","type":"Secondary","score":"1.7","severity":"LOW","vector":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":1.7,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"1.7","severity":"LOW","vector":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","data":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"NONE","baseScore":1.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","version":"3.1"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297470","name":"https://gitlab.com/gitlab-org/gitlab/-/issues/297470","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json","name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"2021/CVE-2021-39911.json · master · GitLab.org / cves · GitLab","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-39911","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39911","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"GitLab","product":"GitLab","version":"affected >=13.9, <14.2.6","platforms":[]},{"source":"CNA","vendor":"GitLab","product":"GitLab","version":"affected >=14.3, <14.3.4","platforms":[]},{"source":"CNA","vendor":"GitLab","product":"GitLab","version":"affected >=14.4, <14.4.1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"This vulnerability has been discovered internally by the GitLab team","lang":"en"}],"nvd_cpes":[{"cve_year":"2021","cve_id":"39911","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"39911","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gitlab","cpe5":"gitlab","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-39911","qid":"376040","title":"GitLab Multiple Security Vulnerabilities (gitlab release-14.2.6,14.3.4,14.4.1)"},{"cve":"CVE-2021-39911","qid":"690230","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for gitlab (33557582-3958-11ec-90ba-001b217b3468)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-04T02:20:33.804Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297470"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"GitLab","vendor":"GitLab","versions":[{"status":"affected","version":">=13.9, <14.2.6"},{"status":"affected","version":">=14.3, <14.3.4"},{"status":"affected","version":">=14.4, <14.4.1"}]}],"credits":[{"lang":"en","value":"This vulnerability has been discovered internally by the GitLab team"}],"descriptions":[{"lang":"en","value":"An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers"}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"NONE","baseScore":1.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"description":"Exposure of private information ('privacy violation') in GitLab","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2022-05-12T20:21:33.000Z","orgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","shortName":"GitLab"},"references":[{"tags":["x_refsource_MISC"],"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297470"},{"tags":["x_refsource_CONFIRM"],"url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@gitlab.com","ID":"CVE-2021-39911","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"GitLab","version":{"version_data":[{"version_value":">=13.9, <14.2.6"},{"version_value":">=14.3, <14.3.4"},{"version_value":">=14.4, <14.4.1"}]}}]},"vendor_name":"GitLab"}]}},"credit":[{"lang":"eng","value":"This vulnerability has been discovered internally by the GitLab team"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers"}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"NONE","baseScore":1.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Exposure of private information ('privacy violation') in GitLab"}]}]},"references":{"reference_data":[{"name":"https://gitlab.com/gitlab-org/gitlab/-/issues/297470","refsource":"MISC","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/297470"},{"name":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json","refsource":"CONFIRM","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39911.json"}]}}}},"cveMetadata":{"assignerOrgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","assignerShortName":"GitLab","cveId":"CVE-2021-39911","datePublished":"2021-11-04T23:16:02.000Z","dateReserved":"2021-08-23T00:00:00.000Z","dateUpdated":"2024-08-04T02:20:33.804Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2021-11-05 00:15:11","lastModifiedDate":"2026-06-12 14:34:00","problem_types":["NVD-CWE-Other","Exposure of private information ('privacy violation') in GitLab"],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N","baseScore":1.7,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.3,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"14.2.6","matchCriteriaId":"2A1127EE-4C28-4D65-B3C9-C6A3A9A0D8B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.9.0","versionEndExcluding":"14.2.6","matchCriteriaId":"0DF10F51-D41C-4F2E-88DF-CD940B3693A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"89D408A9-D433-4674-9EFF-94C13094C8D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.3.0","versionEndExcluding":"14.3.4","matchCriteriaId":"79C91F49-B540-4D22-8CC9-E5CAD399E520"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"39911","Ordinal":"1","Title":"CVE-2021-39911","CVE":"CVE-2021-39911","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"39911","Ordinal":"1","NoteData":"An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data consumers","Type":"Description","Title":"CVE-2021-39911"},{"CveYear":"2021","CveId":"39911","Ordinal":"2","NoteData":"2021-11-04","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"39911","Ordinal":"3","NoteData":"2021-11-04","Type":"Other","Title":"Modified"}]}}}