QID 376097
Date Published: 2021-11-25
QID 376097: GitLab Multiple Security Vulnerabilities (gitlab- 14.3.1, 14.2.5, 14.1.7)
GitLab, the software, is a web-based Git repository manager with wiki and issue tracking features.
The GitLab update fixes the following vulnerabilities:
Affected Version:
All versions Prior to 14.3.1
All versions Prior to 14.2.5
All versions Prior to 14.1.7
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability to expose sensitive information
Solution
The vendor has released patch, For more information please visit GitLab advisory
Vendor References
CVEs related to QID 376097
CVE-2021-39885 | CVE-2021-39877 | CVE-2021-39887 | CVE-2021-39867 | CVE-2021-39869 | CVE-2021-39872 | CVE-2021-39891 | CVE-2021-39878 | CVE-2021-39894 | CVE-2021-39866 | CVE-2021-39882 | CVE-2021-39893 | CVE-2021-39875 | CVE-2021-39870 | CVE-2021-39884 | CVE-2021-39888 | CVE-2021-39883 | CVE-2021-39889 | CVE-2021-39892 | CVE-2021-22259 | CVE-2021-39868 | CVE-2021-39871 | CVE-2021-39874 | CVE-2021-39873 | CVE-2021-39896 | CVE-2021-39881 | CVE-2021-39890 | CVE-2021-39899 | CVE-2021-39886 | CVE-2021-39879 | CVE-2021-39900 |
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Release |
|