PT-2021-22749 · Gitlab · Gitlab Ce/Ee+1

·

CVE-2021-39902

·

Published

2021-11-04

·

Updated

2024-03-06

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.4 and above
Description The issue allows a user with guest membership in a project to modify the severity of an incident due to incorrect authorization.
Recommendations For GitLab CE/EE versions 13.4 and above, update to a version that includes the fix for this issue to prevent unauthorized modification of incident severity.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39902
CVE-2021-39902

Affected Products

Gitlab
Gitlab Ce/Ee