ZeroHour

CVE-2021-39886

CVSS 3.1
4.3 medium
EPSS
<1%p45
Published
()
Modified
Description

Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references.

Vendors
gitlab
Products
gitlab
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.