#VU57938 Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2021-39903
Published: November 4, 2021
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote authenticated attacker can change the visibility level of a group or a project to a restricted option even after the instance administrator sets that visibility option as restricted in settings.