MEDIUM
CVE-2021-39869
CVSS
6.5
Description
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
Summary dbcve.org
In all GitLab CE/EE versions since 8.9, the project export functionality includes trigger tokens configured on the project in the exported data. Trigger tokens are sensitive credentials used for CI/CD pipeline triggering and should remain confidential. This exposure could allow an attacker with access to exported project data to obtain these tokens.
Mitigation
Upgrade to the patched version of GitLab. Until then, restrict access to project exports to trusted users only and rotate any trigger tokens that may have been exposed through past exports.
EPSS Score
1.27%
Probability of exploitation in next 30 days
68.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.