MEDIUM

CVE-2021-22184

Gitlab GitLab 2021-03-26 CVSS v3.1
CVSS
5.5

Description

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

Summary dbcve.org

GitLab versions 12.8 and later contain an information disclosure vulnerability where sensitive information in server logs was not properly redacted, allowing users with server log access to view potentially sensitive data.

Mitigation

Upgrade GitLab to the patched version. Restrict access to server logs pending the upgrade.

Weakness (CWE)

CWE-532 Sensitive Information in Logs

EPSS Score

0.3%
Probability of exploitation in next 30 days
23.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE