Related Vulnerabilities: CVE-2021-39900  

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

Severity Low

Remote Yes

Type Information disclosure

Description

Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

AVG-2431 gitlab 14.3.0-1 14.3.1-1 High Fixed

https://about.gitlab.com/releases/2021/09/30/security-release-gitlab-14-3-1-released/#information-disclosure-in-sendentry
https://gitlab.com/gitlab-org/gitlab/-/issues/325088