« Back to list

CVE-2021-39919

Status: ModifiedMedium (4.4)—

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2021-39919",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@gitlab.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@gitlab.com",
      "affectedData": [
        {
          "vendor": "GitLab",
          "product": "GitLab",
          "versions": [
            {
              "status": "affected",
              "version": ">=14.0, <14.3.6"
            },
            {
              "status": "affected",
              "version": ">=14.4, <14.4.4"
            },
            {
              "status": "affected",
              "version": ">=14.5, <14.5.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-12-13T16:15:09.027",
  "references": [
    {
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39919.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/342445",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39919.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/342445",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-640"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure."
    },
    {
      "lang": "es",
      "value": "En todas las versiones de GitLab CE/EE a partir de versión 14.0 anteriores a 14.3.6, todas las versiones a partir de 14.4 anteriores a 14.4.4, todas las versiones a partir de 14.5 anteriores a 14.5.2, el token de restablecimiento de contraseña y el token de correo electrónico del nuevo usuario son registradas accidentalmente, lo que puede conllevar a una divulgación de información"
    }
  ],
  "lastModified": "2026-06-17T04:04:25.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FA5A64E-6E36-4F36-B106-87EBA9CC8CA6",
              "versionEndExcluding": "14.3.6",
              "versionStartIncluding": "14.0.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65C592BC-4B95-4190-9649-0CA04024B62F",
              "versionEndExcluding": "14.3.6",
              "versionStartIncluding": "14.0.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E801B5F-9C94-4CB2-89ED-D071E567132C",
              "versionEndExcluding": "14.4.4",
              "versionStartIncluding": "14.4.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C38F838-02EA-4E2F-8493-57DD401EF911",
              "versionEndExcluding": "14.4.4",
              "versionStartIncluding": "14.4.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95F59DF7-707C-4C43-8352-8115DAF1C533",
              "versionEndExcluding": "14.5.2",
              "versionStartIncluding": "14.5.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64F26CC0-C99A-4748-963B-944F39E4B647",
              "versionEndExcluding": "14.5.2",
              "versionStartIncluding": "14.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@gitlab.com"
}