MEDIUM

CVE-2024-7554

Gitlab GitLab 2024-08-08 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner.

Summary dbcve.org

In affected GitLab CE/EE versions (13.9 through 17.2.1), access tokens can be inadvertently written to application logs when API requests are made using a specific request method or pattern. This exposes sensitive authentication credentials through log files.

Mitigation

Upgrade GitLab to version 17.0.6, 17.1.4, or 17.2.2 or later. Review existing application logs for exposed tokens and rotate any credentials that may have been logged.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

0.4%
Probability of exploitation in next 30 days
34.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE