vulnerability

FreeBSD: VID-33557582-3958-11ec-90ba-001b217b3468 (CVE-2021-39909): Gitlab -- Multiple Vulnerabilities

Severity
3
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
Oct 30, 2021
Added
Nov 4, 2022
Modified
Mar 25, 2026

Description

Gitlab reports: Stored XSS via ipynb files Pipeline schedules on imported projects can be set to automatically active after import Potential Denial of service via Workhorse Improper Access Control allows Merge Request creator to bypass locked status Projects API discloses ID and name of private groups Severity of an incident can be changed by a guest user System root password accidentally written to log file Potential DoS via a malformed TIFF image Bypass of CODEOWNERS Merge Request approval requirement Change project visibility to a restricted option Project exports leak external webhook token value SCIM token is visible after creation Invited group members, with access inherited from parent group, continue to have project access even after invited subgroup is transfered Regular expression denial of service issue when cleaning namespace path Prevent creation of scopeless apps using applications API Webhook data exposes assignee's private email address

Solution

freebsd-upgrade-package-gitlab-ce
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.