MEDIUM

CVE-2024-10240

Gitlab GitLab 2024-11-26 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

Summary dbcve.org

This is an information disclosure vulnerability in GitLab EE where an unauthenticated attacker can read certain merge request details from private projects under specific conditions. The flaw allows exposure of MR metadata without authentication, classified as an information disclosure issue with CVSS 5.3.

Mitigation

Upgrade GitLab EE to version 17.3.7, 17.4.4, 17.5.2 or later to patch this unauthenticated information disclosure vulnerability.

Weakness (CWE)

CWE-497

EPSS Score

0.56%
Probability of exploitation in next 30 days
45.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE