Medium severity4.3NVD Advisory· Published Feb 9, 2022· Updated Jun 17, 2026
CVE-2021-39943
CVE-2021-39943
Description
An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4>=14.5.0, <14.5.2+ 2 more
- (no CPE)range: >=14.5.0, <14.5.2
- (no CPE)range: from 14.1 before 14.3.6, from 14.4 before 14.4.4, from 14.5 before 14.5.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=14.1.0,<14.3.6
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39943.jsonnvdVendor Advisory
- hackerone.com/reports/1375393nvdPermissions RequiredThird Party Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/343604nvdBroken Link
News mentions
0No linked articles in our index yet.