Input validation error in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2021-39895
Published: November 4, 2021
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to pipeline schedules on imported projects can be set to automatically active after import. A remote administrator can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project.
Affected software
Gitlab Community Edition
How to mitigate CVE-2021-39895
Gitlab Community Edition - addressed in versions 14.2.6, 14.3.4, 14.4.1