MEDIUM
CVE-2024-7554
CVSS
6.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.
Summary dbcve.org
In affected GitLab CE/EE versions (13.9 through 17.2.1), access tokens can be inadvertently written to application logs when API requests are made using a specific request method or pattern. This exposes sensitive authentication credentials through log files.
Mitigation
Upgrade GitLab to version 17.0.6, 17.1.4, or 17.2.2 or later. Review existing application logs for exposed tokens and rotate any credentials that may have been logged.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
0.4%
Probability of exploitation in next 30 days
34.4th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.