CVE-2024-7091
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.
Summary dbcve.org
GitLab CE/EE contains an information disclosure vulnerability in the group and project export functionality. Due to improper access controls, a user can potentially view limited information about exports of groups or projects they should not have access to, allowing unauthorized disclosure of metadata about exported content.
Mitigation
Update GitLab to version 17.0.5, 17.1.3, 17.2.1 or later to patch the vulnerability. Follow standard GitLab upgrade procedures for your deployment model.