Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/457912 |
History
Wed, 18 Sep 2024 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 30 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-653 |
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2024-06-26T23:30:40.557Z
Updated: 2024-09-17T17:03:09.769Z
Reserved: 2024-06-25T13:25:40.311Z
Link: CVE-2024-6323
Vulnrichment
Updated: 2024-08-01T21:33:05.449Z
NVD
Status : Modified
Published: 2024-06-27T00:15:13.130
Modified: 2024-11-21T09:49:25.880
Link: CVE-2024-6323
Redhat
No data.