PT-2021-22747 · Gitlab · Gitlab

Published

2021-10-04

·

Updated

2024-03-06

·

CVE-2021-39900

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 10.8 and later
Description The issue allows for information disclosure from SendEntry in GitLab, exposing the full URL of artifacts stored in object-storage. This exposure occurs via Rails logs and is temporary.
Recommendations For GitLab versions 10.8 and later, update to a version that includes a fix for this issue to prevent information disclosure.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39900
CVE-2021-39900

Affected Products

Gitlab