MEDIUM

CVE-2024-9596

Gitlab GitLab 2024-10-10 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.

Summary dbcve.org

An information disclosure vulnerability in GitLab EE allowed unauthenticated attackers to determine the version number of a GitLab instance by making specific requests to the application. This version information could then be used to identify other potential vulnerabilities applicable to that specific version.

Mitigation

Upgrade GitLab to version 17.2.9, 17.3.5, 17.4.2 or later to patch this vulnerability.

Weakness (CWE)

CWE-540

EPSS Score

0.32%
Probability of exploitation in next 30 days
25.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE