PT-2021-22759 · Gitlab · Gitlab Ce/Ee+1

Published

2021-11-04

·

Updated

2024-03-06

·

CVE-2021-39913

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 14.2.6 GitLab CE/EE versions 14.3 through 14.3.3 GitLab CE/EE versions 14.4 through 14.4.0
Description The issue involves the accidental logging of the system root password in the migration log. This allows an attacker with local file system access to obtain system root-level privileges.
Recommendations For versions prior to 14.2.6, update to version 14.2.6 or later. For versions 14.3 through 14.3.3, update to version 14.3.4 or later. For versions 14.4 through 14.4.0, update to version 14.4.1 or later.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39913
CVE-2021-39913

Affected Products

Gitlab
Gitlab Ce/Ee