CVE-2021-39895 affects all versions of GitLab CE/EE since 8.0, allowing an attacker to configure pipeline schedules to be active within a project export. When an unsuspecting user imports such a project, these pipelines become active by default, potentially leading to information disclosure under specific circumstances if the project originates from an untrusted source. The vulnerability has a CVSS score of 4.5 (Medium), indicating a network attack vector with low complexity, requiring high privileges and user interaction to achieve high confidentiality impact. There is no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 14.1.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 8.0.0, < 14.1.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 14.2.0, < 14.2.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 14.2.0, < 14.2.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
14.3.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:14.3.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.