Description
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-26245 | In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch. |
References
History
No history.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-04T02:20:33.622Z
Reserved: 2021-08-23T00:00:00.000Z
Link: CVE-2021-39889
No data.
Status : Modified
Published: 2021-10-05T14:15:07.987
Modified: 2024-11-21T06:20:28.950
Link: CVE-2021-39889
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD