CVE-2021-39947
published 2022-06-06CVE-2021-39947: In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.79%
52.2th percentile
In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | gitlab | — | — |
| gitlab | gitlab_runner | < 14.3.4 | 14.3.4 |
| gitlab | gitlab_runner | — | — |
| gitlab | gitlab_runner | — | — |
| gitlab | gitlab_runner | — | — |
| gitlab | gitlab_runner | — | — |
| gitlab | gitlab_runner | >= 14.4.0 < 14.4.2 | 14.4.2 |
| gitlab | gitlab_runner | >= 14.5.0 < 14.5.2 | 14.5.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
fastdds vulnerabilities
osv·2023-08-24·CVSS 9.1
CVE-2021-38425 fastdds vulnerabilities
fastdds vulnerabilities
It was discovered that Fast DDS incorrectly handled certain inputs.
A remote attacker could possibly use this issue to cause a denial of
service and information exposure. This issue only affected Ubuntu
22.04 LTS. (CVE-2021-38425)
It was discovered that Fast DDS incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash.
(CVE-2023-39534, CVE-2023-39945, CVE-2023-39946, CVE-2023-39947,
CVE-2023-39948, CVE-2023-39949)
GHSA
GHSA-hwx9-v7rw-v3qm: In specific circumstances, trace file buffers in GitLab Runner versions up to 14
ghsa_unreviewed·2022-06-07
CVE-2021-39947 [HIGH] CWE-200 GHSA-hwx9-v7rw-v3qm: In specific circumstances, trace file buffers in GitLab Runner versions up to 14
In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs
OSV
CVE-2021-39947: In specific circumstances, trace file buffers in GitLab Runner versions up to 14
osv·2022-06-06·CVSS 7.5
CVE-2021-39947 [HIGH] CVE-2021-39947: In specific circumstances, trace file buffers in GitLab Runner versions up to 14
In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs
GitLab
CVE-2021-39947: In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descrip
vendor_gitlab·2022-06-06·CVSS 5.3
CVE-2021-39947 [MEDIUM] CVE-2021-39947: In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descrip
CVE-2021-39947: In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-06
Published