CVE-2021-39900: Low severity GitLab GitLab vulnerability
Published Oct 4, 2021
·Updated
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.
Affected Software
6 affected components
GitLab GitLab>=10.8.0<14.1.7
GitLab GitLab>=10.8.0<14.1.7
GitLab GitLab>=14.2.0<14.2.5
GitLab GitLab>=14.2.0<14.2.5
GitLab GitLab=14.3.0
GitLab GitLab=14.3.0
Event History
Oct 4, 2021
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 21, 58461
Event
11:42 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-39900?
CVE-2021-39900 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-39900?
To fix CVE-2021-39900, upgrade GitLab to a version above 14.2.5 or 14.3.0.
3
What impact does CVE-2021-39900 have on GitLab?
CVE-2021-39900 allows information disclosure of full URLs for artifacts stored in object storage.
4
Which versions of GitLab are affected by CVE-2021-39900?
CVE-2021-39900 affects GitLab versions from 10.8.0 up to 14.1.7 and 14.2.0 up to 14.2.5.
5
Is CVE-2021-39900 a remote exploit?
CVE-2021-39900 does not require network access to exploit as it involves exposure through Rails logs.