CVE-2021-22194

In all versions of GitLab, marshalled session keys were being stored in Redis.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

13 Jul 2021, 19:15

Type Values Removed Values Added
Summary In all versions of GitLab starting from 13.7, marshalled session keys were being stored in Redis. In all versions of GitLab, marshalled session keys were being stored in Redis.

Information

Published : 2021-03-26 20:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-22194

Mitre link : CVE-2021-22194

CVE.ORG link : CVE-2021-22194


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-312

Cleartext Storage of Sensitive Information