First published: Mon Jun 06 2022(Updated: )
In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2 would re-use the file descriptor 0 for multiple traces and mix the output of several jobs
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Runner | <14.3.4 | |
GitLab Runner | >=14.4.0<14.4.2 | |
GitLab Runner | >=14.5.0<14.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39947 has a severity rating that typically warrants attention due to potential data mixing between job traces.
To fix CVE-2021-39947, you should upgrade GitLab Runner to a version later than 14.3.4, or greater than or equal to 14.4.3, or 14.5.3.
CVE-2021-39947 affects GitLab Runner versions up to 14.3.4 and between certain ranges of 14.4.x and 14.5.x.
The potential impact of CVE-2021-39947 includes output confusion due to the mixing of trace information from different jobs.
As of the last updates, CVE-2021-39947 is not reported as widely exploited, but it poses a significant risk if left unmitigated.