Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
2021-11-05T00:15:11.373
2024-11-21T06:20:32.683
Modified
CVSSv3.1: 4.4 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 14.2.6 | Yes |
Application | gitlab | gitlab | < 14.2.6 | Yes |
Application | gitlab | gitlab | < 14.3.4 | Yes |
Application | gitlab | gitlab | < 14.3.4 | Yes |
Application | gitlab | gitlab | 14.4.0 | Yes |
Application | gitlab | gitlab | 14.4.0 | Yes |