AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-39904

MEDIUM · CVSS 4.3 EPSS 0.81%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-11-05 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-39904
Severity
MEDIUM
CVSS
4.3
EPSS
0.81%
GitLab

Original NVD Description

An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request