MEDIUM

CVE-2021-39913

Gitlab GitLab 2021-11-05 CVSS v3.1
CVSS
6.7

Description

Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges

Summary dbcve.org

GitLab CE/EE versions before 14.2.6, 14.3.4, and 14.4.1 inadvertently log the system root password in plaintext to migration log files. An attacker with local file system access (via compromised account, another vulnerability, or physical access) can read these logs to obtain the root password and escalate to system root privileges.

Mitigation

Immediately upgrade GitLab to a patched version (14.2.6+, 14.3.4+, or 14.4.1+) and rotate the exposed system root password since it may have been compromised. Review log file permissions to prevent future credential exposure.

Weakness (CWE)

CWE-532 Sensitive Information in Logs

EPSS Score

0.29%
Probability of exploitation in next 30 days
21.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE