MEDIUM
CVE-2021-22190
CVSS
6.5
Description
A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token
Summary dbcve.org
A path traversal vulnerability exists in GitLab Workhorse across all versions, allowing attackers to traverse directories and access sensitive files containing JWT tokens through specially crafted requests.
Mitigation
Update GitLab to the latest patched version that includes the path traversal fix in the Workhorse component.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
1.64%
Probability of exploitation in next 30 days
75.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.