PT-2025-26319 · Gitlab · Gitlab Ce/Ee

Published

2024-04-07

·

Updated

2025-08-12

·

CVE-2024-7586

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab EE versions 17.0 through 17.0.6 GitLab EE versions 17.1 through 17.1.4 GitLab EE versions 17.2 through 17.2.2
Description: An issue was discovered in GitLab EE where webhook deletion audit log preserved auth credentials.
Recommendations: For GitLab EE versions 17.0 through 17.0.6, update to version 17.0.6 or later. For GitLab EE versions 17.1 through 17.1.4, update to version 17.1.4 or later. For GitLab EE versions 17.2 through 17.2.2, update to version 17.2.2 or later.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2025-07594
BIT-GITLAB-2024-7586
CVE-2024-7586

Affected Products

Gitlab Ce/Ee