CVE-2021-39900
04.10.2021, 17:15
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 10.8.0 ≤ 𝑥 < 14.1.7 |
gitlab | gitlab | 10.8.0 ≤ 𝑥 < 14.1.7 |
gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
gitlab | gitlab | 14.2.0 ≤ 𝑥 < 14.2.5 |
gitlab | gitlab | 14.3.0 |
gitlab | gitlab | 14.3.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration