An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/398250 |
History
Thu, 26 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 25 Dec 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL. | |
Title | Exposure of Sensitive Information Due to Incompatible Policies in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-213 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2024-12-25T14:46:47.927Z
Updated: 2024-12-26T18:10:54.988Z
Reserved: 2023-09-21T22:01:20.121Z
Link: CVE-2023-5117
Vulnrichment
Updated: 2024-12-26T18:10:50.582Z
NVD
Status : Received
Published: 2024-12-25T15:15:05.900
Modified: 2024-12-25T15:15:05.900
Link: CVE-2023-5117
Redhat
No data.