PT-2024-4739 · Gitlab · Gitlab Ce/Ee+1

Js_Noob

·

Published

2024-04-18

·

Updated

2024-07-08

·

CVE-2024-3959

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 16.7 through 16.11.5 GitLab CE/EE versions 17.0 through 17.0.3 GitLab CE/EE versions 17.1 through 17.1.1
Description: An issue in GitLab CE/EE allows private job artifacts to be accessed by any user due to improper authorization. This can enable a remote attacker to gain unauthorized access to protected information.
Recommendations: For GitLab CE/EE versions 16.7 through 16.11.5, update to version 16.11.5 or later to resolve the issue. For GitLab CE/EE versions 17.0 through 17.0.3, update to version 17.0.3 or later to resolve the issue. For GitLab CE/EE versions 17.1 through 17.1.1, update to version 17.1.1 or later to resolve the issue.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-05259
BIT-GITLAB-2024-3959
CVE-2024-3959

Affected Products

Gitlab
Gitlab Ce/Ee