CVE-2021-39888
EUVD-2021-2624405.10.2021, 13:15
In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 a specific API endpoint may reveal details about a private group and other sensitive info inside issue and merge request templates.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 13.10.0 ≤ 𝑥 < 14.1.7 |
| gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
| gitlab | gitlab | 14.3.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References