An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
Metrics
Affected Vendors & Products
References
History
Fri, 12 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:*:enterprise:*:* |
Status: PUBLISHED
Assigner: GitLab
Published: 2021-11-04T23:13:11.000Z
Updated: 2024-08-04T02:20:33.680Z
Reserved: 2021-08-23T00:00:00.000Z
Link: CVE-2021-39904
No data.
Status : Modified
Published: 2021-11-05T00:15:10.847
Modified: 2026-06-12T14:34:00.577
Link: CVE-2021-39904
No data.