VYPR
Medium severity4.4NVD Advisory· Published Nov 5, 2021· Updated Jun 17, 2026

CVE-2021-39913

CVE-2021-39913

Description

Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges

Affected products

5
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <14.2.6
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <14.2.6
    • (no CPE)range: <14.2.6
  • Range: <14.2.6, 14.3<14.3.4, 14.4<14.4.1
  • osv-coords
    Range: < 14.2.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.