PT-2021-14920 · Gitlab · Gitlab
Published
2021-10-05
·
Updated
2024-03-06
·
CVE-2021-22258
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
GitLab versions 8.9 and greater
Description:
The project import/export feature could be used to obtain otherwise private email addresses.
Recommendations:
For GitLab versions 8.9 and greater, consider restricting access to the project import/export feature until a fix is available. As a temporary workaround, limit the use of this feature to minimize the risk of exposing private email addresses.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab