PT-2024-5973 · Gitlab · Gitlab Ce/Ee+1

Eugenia Grieff

·

Published

2024-04-23

·

Updated

2024-09-05

·

CVE-2024-7091

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.6 through 17.0.5 GitLab CE/EE versions 17.1 through 17.1.3 GitLab CE/EE versions 17.2 through 17.2.1
Description An issue in GitLab CE/EE allows disclosure of limited information of an exported group or project to another user. The issue is related to authorization procedure shortcomings, which can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations For versions 15.6 through 17.0.5, update to version 17.0.5 or later. For versions 17.1 through 17.1.3, update to version 17.1.3 or later. For versions 17.2 through 17.2.1, update to version 17.2.1 or later.

Exploit

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-06781
BIT-GITLAB-2024-7091
CVE-2024-7091

Affected Products

Gitlab
Gitlab Ce/Ee