CVE-2021-39900
04.10.2021, 17:15
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 10.8.0 ≤ 𝑥 < 14.1.7 |
| gitlab | gitlab | 10.8.0 ≤ 𝑥 < 14.1.7 |
| gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
| gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
| gitlab | gitlab | 14.3.0 |
| gitlab | gitlab | 14.3.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration