VYPR
Low severity3.8NVD Advisory· Published Oct 4, 2021· Updated Jun 17, 2026

CVE-2021-39896

CVE-2021-39896

Description

In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user they impersonated, which may lead to repudiation issues.

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.0.0,<14.1.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.0.0,<14.1.7
    • (no CPE)range: >=8.0
    • (no CPE)range: >=8.0, <14.1.7
  • osv-coords
    Range: >= 8.0.0, < 14.1.7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.