← Back to browse · API

CVE-2021-39935

Severity
MEDIUM
CVSS
6.8
EPSS
0.35649
Risk score
64.68
CISA KEV
Yes
PoC
No
Published
2021-12-13
Modified
2026-02-03
First seen
2026-08-07
Aliases
EUVD-2021-26291, GHSA-22HJ-9CX7-P2HW
Products
GitLab:Community and Enterprise Editions, GitLab:GitLab 10.5, <14.3.6, GitLab:GitLab 14.4, <14.4.4, GitLab:GitLab 14.5, <14.5.2
Sources
euvd EUVD-2021-26291
cisa.gov CVE-2021-39935

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

References