PT-2021-22747 · Gitlab · Gitlab

CVE-2021-39900

·

Published

2021-10-04

·

Updated

2024-03-06

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 10.8 and later
Description The issue allows for information disclosure from SendEntry in GitLab, exposing the full URL of artifacts stored in object-storage. This exposure occurs via Rails logs and is temporary.
Recommendations For GitLab versions 10.8 and later, update to a version that includes a fix for this issue to prevent information disclosure.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2021-39900
CVE-2021-39900

Affected Products

Gitlab