CVE-2021-22184: Medium severity gitlab vulnerability
Published Mar 26, 2021
·Updated
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.
Affected Software
6 affected components
GitLab GitLab>=12.8.0<13.6.6
GitLab GitLab>=12.8.0<13.6.6
GitLab GitLab>=13.7.0<13.7.6
GitLab GitLab>=13.7.0<13.7.6
GitLab GitLab>=13.8.0<13.8.2
GitLab GitLab>=13.8.0<13.8.2
Event History
Mar 26, 2021
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22184?
CVE-2021-22184 has a medium severity level due to its potential for information disclosure.
2
How do I fix CVE-2021-22184?
To fix CVE-2021-22184, upgrade GitLab to version 13.6.6 or higher for a recommended resolution.
3
What versions of GitLab are affected by CVE-2021-22184?
CVE-2021-22184 affects GitLab versions from 12.8.0 up to but not including 13.8.2.
4
What type of information is disclosed in CVE-2021-22184?
CVE-2021-22184 allows exposure of sensitive information within the server logs that is not properly redacted.
5
Is user action required to mitigate CVE-2021-22184?
Yes, users must update their GitLab installation to mitigate the vulnerability associated with CVE-2021-22184.