MEDIUM

CVE-2024-7091

Gitlab GitLab 2024-07-24 CVSS v3.1
CVSS
5

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

Summary dbcve.org

GitLab CE/EE contains an information disclosure vulnerability in the group and project export functionality. Due to improper access controls, a user can potentially view limited information about exports of groups or projects they should not have access to, allowing unauthorized disclosure of metadata about exported content.

Mitigation

Update GitLab to version 17.0.5, 17.1.3, 17.2.1 or later to patch the vulnerability. Follow standard GitLab upgrade procedures for your deployment model.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

0.31%
Probability of exploitation in next 30 days
24.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE