MEDIUM

CVE-2021-39869

Gitlab GitLab 2021-10-05 CVSS v3.1
CVSS
6.5

Description

In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.

Summary dbcve.org

In all GitLab CE/EE versions since 8.9, the project export functionality includes trigger tokens configured on the project in the exported data. Trigger tokens are sensitive credentials used for CI/CD pipeline triggering and should remain confidential. This exposure could allow an attacker with access to exported project data to obtain these tokens.

Mitigation

Upgrade to the patched version of GitLab. Until then, restrict access to project exports to trusted users only and rotate any trigger tokens that may have been exposed through past exports.

EPSS Score

1.27%
Probability of exploitation in next 30 days
68.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE