CVE-2021-39901
05.11.2021, 00:15
In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visiting a specific endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 11.10.0 ≤ 𝑥 < 14.2.6 |
gitlab | gitlab | 11.10.0 ≤ 𝑥 < 14.2.6 |
gitlab | gitlab | 14.3.0 ≤ 𝑥 < 14.3.4 |
gitlab | gitlab | 14.3.0 ≤ 𝑥 < 14.3.4 |
gitlab | gitlab | 14.4.0 |
gitlab | gitlab | 14.4.0 |
𝑥
= Vulnerable software versions
References