Описание
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
Ссылки
- Vendor Advisory
- Broken LinkIssue TrackingVendor Advisory
- Vendor Advisory
- Broken LinkIssue TrackingVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
4.4 Medium
CVSS3
6.7 Medium
CVSS3
7.2 High
CVSS2
Дефекты
Связанные уязвимости
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
Accidental logging of system root password in the migration log in all ...
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE allows an attacker with local file system access to obtain system root-level privileges
EPSS
4.4 Medium
CVSS3
6.7 Medium
CVSS3
7.2 High
CVSS2