AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-39895

MEDIUM · CVSS 6 EPSS 0.98%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-11-05 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-39895
Severity
MEDIUM
CVSS
6
EPSS
0.98%
GitLab

Original NVD Description

In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to information disclosure if the project is imported from an untrusted source.