Insufficient Session Expiration in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2021-39896
Published: October 5, 2021
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper session management in impersonation feature. A remote administrator can use the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2021-39896
GitLab Enterprise Edition - addressed in versions 14.1.7, 14.2.5, 14.3.1