MEDIUM
CVE-2024-5435
CVSS
6.5
Description
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.
Summary dbcve.org
GitLab EE/CE versions 15.10 through 17.3.1 contain an information disclosure vulnerability where user passwords stored in repository mirror configuration can be exposed to unauthorized parties.
Mitigation
Upgrade GitLab to version 17.1.7, 17.2.5, or 17.3.2 or later to patch the password disclosure in repository mirror settings.
Weakness (CWE)
CWE-209
EPSS Score
0.46%
Probability of exploitation in next 30 days
38.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.