Improper access control in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2021-39903
Published: November 4, 2021
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote authenticated attacker can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.
Affected software
Gitlab Community Edition
How to mitigate CVE-2021-39903
Gitlab Community Edition - addressed in versions 14.2.6, 14.3.4, 14.4.1