Improper access control in GitLab Enterprise Edition - CVE-2021-39916
Published: December 9, 2021
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the External Status Check feature. A remote authenticated attacker can bypass implemented security restrictions and retrieve the configuration of any External Status Check.