{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "An authorization logic error in the External Status Check API in GitLab EE",
    "tracking": {
      "current_release_date": "2026-08-11T15:00:35+00:00",
      "generator": {
        "date": "2026-08-11T15:00:35+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-39943",
      "initial_release_date": "2022-02-10T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T15:00:35+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.12",
            "product": {
              "name": "OpenShift Container Platform 4.12",
              "product_id": "openshift-4.12.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.12"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.13",
            "product": {
              "name": "OpenShift Container Platform 4.13",
              "product_id": "openshift-4.13.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.13"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.14",
            "product": {
              "name": "OpenShift Container Platform 4.14",
              "product_id": "openshift-4.14.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.14"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.15.z",
            "product": {
              "name": "OpenShift Container Platform 4.15.z",
              "product_id": "openshift-4.15.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.15"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.16.z",
            "product": {
              "name": "OpenShift Container Platform 4.16.z",
              "product_id": "openshift-4.16.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.16"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.17",
            "product": {
              "name": "OpenShift Container Platform 4.17",
              "product_id": "openshift-4.17",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.17"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.18",
            "product": {
              "name": "OpenShift Container Platform 4.18",
              "product_id": "openshift-4.18",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.18"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.19",
            "product": {
              "name": "OpenShift Container Platform 4.19",
              "product_id": "openshift-4.19",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.19"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.20",
            "product": {
              "name": "OpenShift Container Platform 4.20",
              "product_id": "openshift-4.20",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.20"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift4/ose-console",
            "product": {
              "name": "openshift4/ose-console",
              "product_id": "openshift4/ose-console",
              "product_identification_helper": {
                "purl": "pkg:oci/ose-console?repository_url=registry.redhat.io/openshift4/ose-console"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.15.z",
          "product_id": "openshift-4.15.z:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.15.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.14",
          "product_id": "openshift-4.14.z:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.14.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.13",
          "product_id": "openshift-4.13.z:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.13.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.12",
          "product_id": "openshift-4.12.z:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.12.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.20",
          "product_id": "openshift-4.20:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.16.z",
          "product_id": "openshift-4.16.z:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.16.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.17",
          "product_id": "openshift-4.17:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.17"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.19",
          "product_id": "openshift-4.19:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.19"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-console as a component of OpenShift Container Platform 4.18",
          "product_id": "openshift-4.18:openshift4/ose-console"
        },
        "product_reference": "openshift4/ose-console",
        "relates_to_product_reference": "openshift-4.18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-39943",
      "cwe": {
        "id": "CWE-639",
        "name": "Authorization Bypass Through User-Controlled Key"
      },
      "discovery_date": "2022-02-10T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "openshift-4.12.z:openshift4/ose-console",
            "openshift-4.13.z:openshift4/ose-console",
            "openshift-4.14.z:openshift4/ose-console",
            "openshift-4.15.z:openshift4/ose-console",
            "openshift-4.16.z:openshift4/ose-console",
            "openshift-4.17:openshift4/ose-console",
            "openshift-4.18:openshift4/ose-console",
            "openshift-4.19:openshift4/ose-console",
            "openshift-4.20:openshift4/ose-console"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "The GitLab package used in OpenShift is a GitLab API NodeJS library which is not affected by CVE-2021-39943.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "openshift-4.12.z:openshift4/ose-console",
          "openshift-4.13.z:openshift4/ose-console",
          "openshift-4.14.z:openshift4/ose-console",
          "openshift-4.15.z:openshift4/ose-console",
          "openshift-4.16.z:openshift4/ose-console",
          "openshift-4.17:openshift4/ose-console",
          "openshift-4.18:openshift4/ose-console",
          "openshift-4.19:openshift4/ose-console",
          "openshift-4.20:openshift4/ose-console"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-39943"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39943"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-39943"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "openshift-4.12.z:openshift4/ose-console",
            "openshift-4.13.z:openshift4/ose-console",
            "openshift-4.14.z:openshift4/ose-console",
            "openshift-4.15.z:openshift4/ose-console",
            "openshift-4.16.z:openshift4/ose-console",
            "openshift-4.17:openshift4/ose-console",
            "openshift-4.18:openshift4/ose-console",
            "openshift-4.19:openshift4/ose-console",
            "openshift-4.20:openshift4/ose-console"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "openshift-4.12.z:openshift4/ose-console",
            "openshift-4.13.z:openshift4/ose-console",
            "openshift-4.14.z:openshift4/ose-console",
            "openshift-4.15.z:openshift4/ose-console",
            "openshift-4.16.z:openshift4/ose-console",
            "openshift-4.17:openshift4/ose-console",
            "openshift-4.18:openshift4/ose-console",
            "openshift-4.19:openshift4/ose-console",
            "openshift-4.20:openshift4/ose-console"
          ]
        }
      ],
      "title": "An authorization logic error in the External Status Check API in GitLab EE"
    }
  ]
}