CVE-2021-39872
6.5
MEDIUM
CVSS 3.1
EPSS 0.21%
Description
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password expiration.
How to fix CVE-2021-39872
To remediate CVE-2021-39872, upgrade the affected package to a fixed version below.
- Bitnami/gitlab—upgrade to 14.1.7 or later
Is CVE-2021-39872 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 14.1.0, < 14.1.7, >= 14.2.0, < 14.2.5, >= 14.3.0, < 14.3.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |