MEDIUM

CVE-2021-22190

Gitlab GitLab 2021-04-12 CVSS v3.1
CVSS
6.5

Description

A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token

Summary dbcve.org

A path traversal vulnerability exists in GitLab Workhorse across all versions, allowing attackers to traverse directories and access sensitive files containing JWT tokens through specially crafted requests.

Mitigation

Update GitLab to the latest patched version that includes the path traversal fix in the Workhorse component.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

1.64%
Probability of exploitation in next 30 days
75.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE