Medium severity4.3NVD Advisory· Published Dec 13, 2021· Updated Jun 17, 2026
CVE-2021-39916
CVE-2021-39916
Description
Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=14.1.0,<14.3.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=14.1.0,<14.3.6
- (no CPE)range: >=14.1 <14.3.6, >=14.4 <14.4.4, >=14.5 <14.5.2
- (no CPE)range: >=14.1, <14.3.6
- Range: >=14.1 <14.3.6, >=14.4 <14.4.4, >=14.5 <14.5.2
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39916.jsonnvdVendor Advisory
- hackerone.com/reports/1372216nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/343379nvdBroken Link
News mentions
0No linked articles in our index yet.