Gitlab · Gitlab Ce/Ee · CVE-2024-6389
**Name of the Vulnerable Software and Affected Versions**
GitLab-CE/EE versions 17.0 through 17.1.7
GitLab-CE/EE versions 17.2 through 17.2.5
GitLab-CE/EE versions 17.3 through 17.3.2
**Description**
An issue was discovered in GitLab-CE/EE where an attacker, as a guest user, was able to access commit information via the "release Atom endpoint", contrary to permissions.
**Recommendations**
For versions 17.0 through 17.1.7, update to version 17.1.7 or later.
For versions 17.2 through 17.2.5, update to version 17.2.5 or later.
For versions 17.3 through 17.3.2, update to version 17.3.2 or later.
As a temporary workaround, consider restricting access to the release Atom endpoint until a patch is available.