CVE-2021-39895
4.5
MEDIUM
CVSS 3.1
EPSS 0.28%
Description
In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source.
How to fix CVE-2021-39895
To remediate CVE-2021-39895, upgrade the affected package to a fixed version below.
- —upgrade to 14.1.7 or later
Is CVE-2021-39895 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 8.0.0, < 14.1.7, >= 14.2.0, < 14.2.5, >= 14.3.0, < 14.3.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.5 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N |