CVE-2021-22194 — Cleartext Storage of Sensitive Info in Gitlab
Severity
4.4MEDIUMNVD
EPSS
0.0%
top 89.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 26
Latest updateMay 24
Description
In all versions of GitLab, marshalled session keys were being stored in Redis.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6