CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It affects GitLab.
CVE
CVE-2021-39909
Severity
MEDIUM
CVSS
5.3
EPSS
0.59%
GitLab
Original NVD Description
Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances
Related CVEs
Other vulnerabilities affecting the same vendor(s)