All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
2021-06-08T19:15:08.100
2024-11-21T05:49:44.067
Modified
CVSSv3.1: 4.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 13.10.5 | Yes |
Application | gitlab | gitlab | < 13.10.5 | Yes |
Application | gitlab | gitlab | < 13.11.5 | Yes |
Application | gitlab | gitlab | < 13.11.5 | Yes |
Application | gitlab | gitlab | < 13.12.2 | Yes |
Application | gitlab | gitlab | < 13.12.2 | Yes |