Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34422 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint. |
Solution
Upgrade to versions 17.6.4, 17.7.3, 17.8.1 or above.
Workaround
No workaround given by the vendor.
Tue, 05 Aug 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:enterprise:*:*:* |
Wed, 05 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 24 Jan 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint. | |
| Title | Insufficient Granularity of Access Control in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-1220 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-02-05T20:14:21.196Z
Reserved: 2024-11-27T20:02:05.948Z
Link: CVE-2024-11931
Updated: 2025-02-05T20:14:17.026Z
Status : Analyzed
Published: 2025-01-24T03:15:06.590
Modified: 2025-08-05T19:57:08.360
Link: CVE-2024-11931
No data.
OpenCVE Enrichment
No data.
EUVD