CVE-2021-22219
Status: ModifiedMedium (4.9)—
All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Base score: 4.9
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.95%
- Percentile among all scored CVEs: 60
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-532
References
Raw JSON (NVD)
Show
{
"id": "CVE-2021-22219",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@gitlab.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.7
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "cve@gitlab.com",
"affectedData": [
{
"vendor": "GitLab",
"product": "GitLab",
"versions": [
{
"status": "affected",
"version": ">=9.5, <13.10.5"
},
{
"status": "affected",
"version": ">=13.11, <13.11.5"
},
{
"status": "affected",
"version": ">=13.12, <13.12.2"
}
]
}
]
}
],
"published": "2021-06-08T19:15:08.100",
"references": [
{
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22219.json",
"tags": [
"Vendor Advisory"
],
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/296995",
"tags": [
"Broken Link"
],
"source": "cve@gitlab.com"
},
{
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22219.json",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/296995",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "All versions of GitLab CE/EE starting from 9.5 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 allow a high privilege user to obtain sensitive information from log files because the sensitive information was not correctly registered for log masking."
},
{
"lang": "es",
"value": "Todas las versiones de GitLab CE/EE a partir de la 9.5 antes de la 13.10.5, todas las versiones a partir de la 13.11 antes de la 13.11.5 y todas las versiones a partir de la 13.12 antes de la 13.12.2 permiten que un usuario con altos privilegios obtenga información sensible de los archivos de registro porque la información sensible no se registró correctamente para el enmascaramiento del registro"
}
],
"lastModified": "2026-06-17T03:36:49.813",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D4E8053F-4A2A-4BD2-AB46-2B7F757B1153",
"versionEndExcluding": "13.10.5",
"versionStartIncluding": "9.5.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F4DD7DA7-CB28-48C4-8CD0-AA8BCE4E4CEB",
"versionEndExcluding": "13.10.5",
"versionStartIncluding": "9.5.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "299084AF-AA62-4503-B9E8-3D44898553DF",
"versionEndExcluding": "13.11.5",
"versionStartIncluding": "13.11.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36C14C68-B2DB-4EDB-9604-764D5CEC8C2C",
"versionEndExcluding": "13.11.5",
"versionStartIncluding": "13.11.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F16BCB65-EA10-492B-B921-5F90632BA5E5",
"versionEndExcluding": "13.12.2",
"versionStartIncluding": "13.12.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3020FB1-3219-41FB-9E06-282E9F8075DD",
"versionEndExcluding": "13.12.2",
"versionStartIncluding": "13.12.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@gitlab.com"
}