PT-2024-7212 · Gitlab · Gitlab Ce/Ee+1

Paul Gascou-Vaillancourt

·

Published

2024-10-09

·

Updated

2024-10-16

·

CVE-2024-9596

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 16.6 through 17.2.9 GitLab EE versions 17.3 through 17.3.5 GitLab EE versions 17.4 through 17.4.2
Description An issue has been discovered in GitLab EE, allowing an unauthenticated attacker to determine the GitLab version number for a GitLab instance. This is related to insufficient protection of service data in the source code, which may allow a remote attacker to gain unauthorized access to protected information.
Recommendations For GitLab EE versions 16.6 through 17.2.9, update to version 17.2.9 or later. For GitLab EE versions 17.3 through 17.3.5, update to version 17.3.5 or later. For GitLab EE versions 17.4 through 17.4.2, update to version 17.4.2 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-08551
BIT-GITLAB-2024-9596
CVE-2024-9596

Affected Products

Gitlab
Gitlab Ce/Ee