Gitlab · Gitlab Ce/Ee · CVE-2024-7091
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 15.6 through 17.0.5
GitLab CE/EE versions 17.1 through 17.1.3
GitLab CE/EE versions 17.2 through 17.2.1
**Description**
An issue in GitLab CE/EE allows disclosure of limited information of an exported group or project to another user. The issue is related to authorization procedure shortcomings, which can be exploited by a remote attacker to gain unauthorized access to protected information.
**Recommendations**
For versions 15.6 through 17.0.5, update to version 17.0.5 or later.
For versions 17.1 through 17.1.3, update to version 17.1.3 or later.
For versions 17.2 through 17.2.1, update to version 17.2.1 or later.