Vulnerabilities > CVE-2021-39889 - Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint may reveal the protected branch name to a malicious user who makes a crafted API call with the ID of the protected branch.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 13 |