{ "id": "CVE-2021-39880", "sourceIdentifier": "cve@gitlab.com", "published": "2021-10-05T15:15:07.727", "lastModified": "2022-10-19T18:25:02.617", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to deny access to all users via specially crafted requests to the apollo_upload_server middleware." }, { "lang": "es", "value": "Una vulnerabilidad de denegaci\u00f3n de servicio en la gema apollo_upload_server Ruby en GitLab CE/EE todas las versiones a partir de la 11.9 antes de la 14.0.9, todas las versiones a partir de la 14.1 antes de la 14.1.4, y todas las versiones a partir de la 14.2 antes de la 14.2.2 permite a un atacante denegar el acceso a todos los usuarios a trav\u00e9s de peticiones especialmente dise\u00f1adas al middleware apollo_upload_server" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 3.6 }, { "source": "cve@gitlab.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "versionStartExcluding": "11.9.0", "versionEndExcluding": "14.0.9", "matchCriteriaId": "B3FAD5E0-444A-4E02-90EB-2B566FF5C357" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "versionStartIncluding": "11.9.0", "versionEndExcluding": "14.0.9", "matchCriteriaId": "A06CCFC9-FAC1-4920-8C43-83BB9C3C697B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "versionStartExcluding": "14.1.0", "versionEndExcluding": "14.1.4", "matchCriteriaId": "19C48DA3-9DC3-42D9-904C-A0BCA9444E21" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "versionStartIncluding": "14.1.0", "versionEndExcluding": "14.1.4", "matchCriteriaId": "B0917E00-8A8B-456B-8AF9-FEDE1B16079F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*", "versionStartIncluding": "14.2.0", "versionEndExcluding": "14.2.2", "matchCriteriaId": "3CE159DB-7F83-42A6-9527-EB372B1F0C12" }, { "vulnerable": true, "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "versionStartIncluding": "14.2.0", "versionEndExcluding": "14.2.2", "matchCriteriaId": "9748F8EA-2A15-4F22-8C54-5CA56B75EA58" } ] } ] } ], "references": [ { "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39880.json", "source": "cve@gitlab.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/330561", "source": "cve@gitlab.com", "tags": [ "Broken Link" ] }, { "url": "https://hackerone.com/reports/1181284", "source": "cve@gitlab.com", "tags": [ "Permissions Required", "Third Party Advisory" ] } ] }