An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.
History

Tue, 08 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-662 NVD-CWE-Other

Thu, 26 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-662
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*

Thu, 26 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 06:45:00 +0000

Type Values Removed Values Added
Description An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.
Title Incorrect Synchronization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-821
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2024-09-26T06:30:59.796Z

Updated: 2024-09-26T17:26:34.539Z

Reserved: 2024-04-26T21:30:42.737Z

Link: CVE-2024-4278

cve-icon Vulnrichment

Updated: 2024-09-26T13:40:00.569Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-26T07:15:02.603

Modified: 2024-10-08T19:51:38.403

Link: CVE-2024-4278

cve-icon Redhat

No data.