PT-2021-4077 · Gitlab · Gitlab

Published

2021-01-05

·

Updated

2024-03-06

·

CVE-2021-22206

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 11.6 and later
Description The issue is related to the exposure of pull mirror credentials in GitLab, allowing other maintainers to view the credentials in plain-text. This could potentially enable a remote attacker to gain access to confidential data.
Recommendations For GitLab versions 11.6 and later, update to a version that includes a fix for the exposed pull mirror credentials issue. As a temporary workaround, consider restricting access to the pull mirror credentials to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2021-04655
BIT-GITLAB-2021-22206
CVE-2021-22206

Affected Products

Gitlab