Skip to main content

GitLab Multiple Vulnerabilities

Last Update Date: 4 Feb 2026 Release Date: 8 Dec 2021 11604 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in GitLab, a remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, security restriction bypass and elevation of privilege on the targeted system.

 

Note: CVE-2021-39935 is actively exploited in the wild. An unauthenticated attacker could exploit server-side request forgery vulnerability, leading to security restriction bypass. Hence, the risk level is rated as High Risk.

 

[Updated on 2026-02-04]

Updated Description, Related Links and Risk Level. 


Impact

  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 14.5.2, 14.4.4, and 14.3.6
  • GitLab Enterprise Edition (EE) versions prior to 14.5.2, 14.4.4, and 14.3.6


Solutions

Before installation of the software, please visit the software vendor web-site for more details.


Vulnerability Identifier


Source


Related Link