CVE Vulnerabilities

CVE-2022-1157

Insertion of Sensitive Information into Log File

Published: Apr 11, 2022 | Modified: Nov 21, 2024
CVSS 3.x
2.4
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 of GitLab CE/EE causes potential sensitive values in invalid URLs to be logged

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab*14.7.7 (excluding)
GitlabGitlab14.8.0 (including)14.8.5 (excluding)
GitlabGitlab14.9.0 (including)14.9.2 (excluding)
GitlabUbuntuesm-apps/xenial*
GitlabUbuntuupstream*

Potential Mitigations

References