PT-2024-5516 · Gitlab · Gitlab Ce/Ee+1

Published

2024-08-07

·

Updated

2024-08-29

·

CVE-2024-7554

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.9 through 17.0.6 GitLab CE/EE versions 17.1 through 17.1.4 GitLab CE/EE versions 17.2 through 17.2.2
Description An issue has been discovered in GitLab CE/EE where access tokens may have been logged when an API request was made in a specific manner. This is related to insufficient protection of service data when processing request parameters. Exploitation of this issue may allow a remote attacker to disclose protected information by sending specially crafted API requests.
Recommendations For GitLab CE/EE versions 13.9 through 17.0.6, update to a version after 17.0.6 to resolve the issue. For GitLab CE/EE versions 17.1 through 17.1.4, update to a version after 17.1.4 to resolve the issue. For GitLab CE/EE versions 17.2 through 17.2.2, update to a version after 17.2.2 to resolve the issue. As a temporary workaround, consider restricting access to API endpoints that may log access tokens until a patch is available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-06165
BIT-GITLAB-2024-7554
CVE-2024-7554

Affected Products

Gitlab
Gitlab Ce/Ee