CVE-2021-39913 — Log File Information Exposure in Gitlab
Severity
6.7MEDIUMNVD
EPSS
0.1%
top 81.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 5
Latest updateMay 24
Description
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9
Affected Packages5 packages
🔴Vulnerability Details
2GHSA▶
GHSA-hw95-w73v-wf42: Accidental logging of system root password in the migration log in all versions of GitLab CE/EE allows an attacker with local file system access to ob↗2022-05-24
OSV▶
CVE-2021-39913: Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14↗2021-11-05
📋Vendor Advisories
2GitLab▶
CVE-2021-39913: Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before↗2021-11-05
Debian▶
CVE-2021-39913: gitlab - Accidental logging of system root password in the migration log in all versions ...↗2021