An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.
History

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2024-06-26T23:31:25.425Z

Updated: 2024-08-29T15:04:57.412Z

Reserved: 2024-04-18T16:02:36.516Z

Link: CVE-2024-3959

cve-icon Vulnrichment

Updated: 2024-08-01T20:26:57.148Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-27T00:15:11.420

Modified: 2024-06-28T13:21:52.223

Link: CVE-2024-3959

cve-icon Redhat

No data.