MEDIUM
CVE-2021-22184
CVSS
5.5
Description
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.
Summary dbcve.org
GitLab versions 12.8 and later contain an information disclosure vulnerability where sensitive information in server logs was not properly redacted, allowing users with server log access to view potentially sensitive data.
Mitigation
Upgrade GitLab to the patched version. Restrict access to server logs pending the upgrade.
Weakness (CWE)
CWE-532
Sensitive Information in Logs
EPSS Score
0.3%
Probability of exploitation in next 30 days
23.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.