VYPR
Low severity3.5NVD Advisory· Published Jan 18, 2022· Updated Jun 17, 2026

CVE-2021-39927

CVE-2021-39927

Description

Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1 would fail to protect against attacks sending requests to localhost on port 80 or 443 if GitLab was configured to run on a port other than 80 or 443

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.4,<=14.4.5
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.4,<=14.4.5
    • (no CPE)range: between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and between 14.6.0 and 14.6.1
    • (no CPE)range: >=8.4, <14.4.5
  • osv-coords
    Range: >= 8.4.0, < 14.4.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.