CVE Vulnerabilities

CVE-2021-22184

Insertion of Sensitive Information into Log File

Published: Mar 26, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasnt properly redacted.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 12.8.0 (including) 13.6.6 (excluding)
Gitlab Gitlab 13.7.0 (including) 13.7.6 (excluding)
Gitlab Gitlab 13.8.0 (including) 13.8.2 (excluding)

Potential Mitigations

References