CVE Vulnerabilities

CVE-2021-39900

Insertion of Sensitive Information into Log File

Published: Oct 04, 2021 | Modified: Nov 21, 2024
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 10.8.0 (including) 14.1.7 (excluding)
Gitlab Gitlab 14.2.0 (including) 14.2.5 (excluding)
Gitlab Gitlab 14.3.0 (including) 14.3.0 (including)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu xenial *

Potential Mitigations

References