AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-39945

LOW · CVSS 2.7 EPSS 0.91%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-12-13 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.7. It affects GitLab.

CVE
CVE-2021-39945
Severity
LOW
CVSS
2.7
EPSS
0.91%
GitLab

Original NVD Description

Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked

Related CVEs

Other vulnerabilities affecting the same vendor(s)