MEDIUM

CVE-2024-5435

Gitlab GitLab 2024-09-12 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

Summary dbcve.org

GitLab EE/CE versions 15.10 through 17.3.1 contain an information disclosure vulnerability where user passwords stored in repository mirror configuration can be exposed to unauthorized parties.

Mitigation

Upgrade GitLab to version 17.1.7, 17.2.5, or 17.3.2 or later to patch the password disclosure in repository mirror settings.

Weakness (CWE)

CWE-209

EPSS Score

0.46%
Probability of exploitation in next 30 days
38.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE