CVE-2021-22194

In all versions of GitLab, marshalled session keys were being stored in Redis.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

13 Jul 2021, 19:15

Type Values Removed Values Added
Summary In all versions of GitLab starting from 13.7, marshalled session keys were being stored in Redis. In all versions of GitLab, marshalled session keys were being stored in Redis.

30 Mar 2021, 19:57

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
CWE CWE-312
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 4.4
References (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/262107 - (MISC) https://gitlab.com/gitlab-org/gitlab/-/issues/262107 - Broken Link
References (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22194.json - (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22194.json - Vendor Advisory

26 Mar 2021, 20:34

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-26 20:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-22194

Mitre link : CVE-2021-22194

CVE.ORG link : CVE-2021-22194


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-312

Cleartext Storage of Sensitive Information