Related Vulnerabilities: CVE-2021-39939  

GitLab Runner before version 14.5.2 was susceptible to Golang security issue CVE-2021-44717: don’t close fd 0 on ForkExec error, which could result in misdirected I/O such as writing network traffic intended for one connection to a different connection, or content intended for one file to a different one.

Severity Medium

Remote Yes

Type Incorrect calculation

Description

GitLab Runner before version 14.5.2 was susceptible to Golang security issue CVE-2021-44717: don’t close fd 0 on ForkExec error, which could result in misdirected I/O such as writing network traffic intended for one connection to a different connection, or content intended for one file to a different one.

AVG-2619 gitlab-runner 14.5.0-1 Medium Vulnerable

https://about.gitlab.com/releases/2021/12/10/security-release-gitlab-runner-14-5-2-released/