VYPR
Medium severity6.8NVD Advisory· Published May 6, 2021· Updated Jun 17, 2026

CVE-2021-22206

CVE-2021-22206

Description

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.6.0,<13.9.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.6.0,<13.9.7
    • (no CPE)range: >=11.6
    • (no CPE)range: >=11.6, <13.9.7
  • osv-coords
    Range: >= 11.6.0, < 13.9.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.