CVE-2021-22219: Medium severity gitlab vulnerability
All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22219?
CVE-2021-22219 has been classified with a high severity due to its potential to expose sensitive information.
How do I fix CVE-2021-22219?
To fix CVE-2021-22219, upgrade GitLab to version 13.10.5, 13.11.5, or 13.12.2, depending on your current version.
What versions are affected by CVE-2021-22219?
CVE-2021-22219 affects all versions of GitLab CE/EE from 9.5 before 13.10.5, from 13.11 before 13.11.5, and from 13.12 before 13.12.2.
What type of information is exposed by CVE-2021-22219?
CVE-2021-22219 allows high privilege users to obtain sensitive information from log files.
Is CVE-2021-22219 a local or remote vulnerability?
CVE-2021-22219 is considered a local vulnerability, as it requires high privilege access to exploit.