PT-2024-5974 · Gitlab · Gitlab Ce/Ee+1
Yvvdwf
·
Published
2024-04-23
·
Updated
2024-09-05
·
CVE-2024-5067
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab EE versions 16.11 through 17.0.4
GitLab EE versions 17.1 through 17.1.2
GitLab EE versions 17.2 through 17.2.0
Description
The issue is related to insufficient authorization procedures in the Setting Handler component of the GitLab platform, which can allow a remote attacker to gain unauthorized access to protected information. Certain project-level analytics settings could be leaked in the DOM to group members with Developer or higher roles.
Recommendations
For GitLab EE versions 16.11 through 17.0.4, update to version 17.0.5 or later.
For GitLab EE versions 17.1 through 17.1.2, update to version 17.1.3 or later.
For GitLab EE versions 17.2 through 17.2.0, update to version 17.2.1 or later.
Exploit
Fix
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee