Description
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-26232 | In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an API endpoint. |
References
History
No history.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-04T02:20:33.568Z
Reserved: 2021-08-23T00:00:00.000Z
Link: CVE-2021-39875
No data.
Status : Modified
Published: 2021-10-05T13:15:08.143
Modified: 2024-11-21T06:20:26.680
Link: CVE-2021-39875
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD