An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.
History

Thu, 05 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Gitlab
Gitlab gitlab
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2024-07-24T22:08:05.034Z

Updated: 2024-08-29T15:04:59.039Z

Reserved: 2024-05-17T13:30:44.660Z

Link: CVE-2024-5067

cve-icon Vulnrichment

Updated: 2024-08-01T21:03:10.510Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-24T23:15:09.610

Modified: 2024-09-05T17:29:32.287

Link: CVE-2024-5067

cve-icon Redhat

No data.