CVE-2021-39900
EUVD-2021-2625604.10.2021, 17:15
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 10.8.0 ≤ 𝑥 < 14.1.7 |
| gitlab | gitlab | 10.8.0 ≤ 𝑥 < 14.1.7 |
| gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
| gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
| gitlab | gitlab | 14.3.0 |
| gitlab | gitlab | 14.3.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration