PT-2024-6675 · Gitlab · Gitlab Ce/Ee+1

Published

2024-06-25

·

Updated

2024-08-30

·

CVE-2024-6323

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab EE versions 16.11 through 16.11.4 GitLab EE versions 17.0 through 17.0.2 GitLab EE versions 17.1 through 17.1.0
Description: The issue is related to improper authorization in the global search function, allowing an attacker to leak the content of a private repository in a public project. This can be exploited by a remote attacker to disclose protected information.
Recommendations: For GitLab EE versions 16.11 through 16.11.4, update to version 16.11.5 or later. For GitLab EE versions 17.0 through 17.0.2, update to version 17.0.3 or later. For GitLab EE versions 17.1 through 17.1.0, update to version 17.1.1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-07881
BIT-GITLAB-2024-6323
CVE-2024-6323

Affected Products

Gitlab
Gitlab Ce/Ee