CVE Vulnerabilities

CVE-2021-39947

Published: Jun 06, 2022 | Modified: Aug 08, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs

Affected Software

Name Vendor Start Version End Version
Gitlab_runner Gitlab * 14.3.4 (excluding)
Gitlab_runner Gitlab 14.4.0 (including) 14.4.2 (excluding)
Gitlab_runner Gitlab 14.5.0 (including) 14.5.2 (excluding)

References