Medium severity4.4NVD Advisory· Published Nov 5, 2021· Updated Jun 17, 2026
CVE-2021-39913
CVE-2021-39913
Description
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <14.2.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <14.2.6
- (no CPE)range: <14.2.6
- Range: <14.2.6, 14.3<14.3.4, 14.4<14.4.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39913.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/28074nvdBroken LinkIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.