CVE-2021-39886 log

Source
Severity Low
Remote Yes
Type Information disclosure
Description
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7, allowing users to read confidential Epic references.
Group Package Affected Fixed Severity Status Ticket
AVG-2431 gitlab 14.3.0-1 14.3.1-1 High Fixed
References
https://about.gitlab.com/releases/2021/09/30/security-release-gitlab-14-3-1-released/#epic-reference-was-not-updated-while-moved-between-groups
https://gitlab.com/gitlab-org/gitlab/-/issues/330520