#VU57930 Input validation error in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2021-39895
Published: November 4, 2021
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to pipeline schedules on imported projects can be set to automatically active after import. A remote administrator can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project.