Description
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-26247 | In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure. |
References
History
No history.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-04T02:20:33.670Z
Reserved: 2021-08-23T00:00:00.000Z
Link: CVE-2021-39891
No data.
Status : Modified
Published: 2021-10-05T14:15:08.037
Modified: 2024-11-21T06:20:29.250
Link: CVE-2021-39891
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD