CVE-2021-39886 - log back

CVE-2021-39886 edited at 04 Oct 2021 21:16:49
References
https://about.gitlab.com/releases/2021/09/30/security-release-gitlab-14-3-1-released/#epic-reference-was-not-updated-while-moved-between-groups
+ https://gitlab.com/gitlab-org/gitlab/-/issues/330520
CVE-2021-39886 edited at 30 Sep 2021 17:30:11
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
Description
+ Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7, allowing users to read confidential Epic references.
References
+ https://about.gitlab.com/releases/2021/09/30/security-release-gitlab-14-3-1-released/#epic-reference-was-not-updated-while-moved-between-groups
Notes
CVE-2021-39886 created at 30 Sep 2021 17:14:55