Description
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-26269 | Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local file system access to obtain system root-level privileges |
References
History
Fri, 12 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:14.4.0:*:*:*:*:enterprise:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-04T02:20:33.764Z
Reserved: 2021-08-23T00:00:00.000Z
Link: CVE-2021-39913
No data.
Status : Modified
Published: 2021-11-05T00:15:11.373
Modified: 2026-06-17T04:04:24.890
Link: CVE-2021-39913
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-532
Insertion of Sensitive Information into Log File
EUVD