CVE-2021-39913
Description
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
Summary dbcve.org
GitLab CE/EE versions before 14.2.6, 14.3.4, and 14.4.1 inadvertently log the system root password in plaintext to migration log files. An attacker with local file system access (via compromised account, another vulnerability, or physical access) can read these logs to obtain the root password and escalate to system root privileges.
Mitigation
Immediately upgrade GitLab to a patched version (14.2.6+, 14.3.4+, or 14.4.1+) and rotate the exposed system root password since it may have been compromised. Review log file permissions to prevent future credential exposure.