CVE-2021-39919
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead…
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.29% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-640
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39919.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/342445Broken Link
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39919.jsonVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/342445Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.