Description
An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to version 17.0.5, 17.1.3, 17.2.1 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48057 | An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export. |
References
| Link | Providers |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/437894 |
|
History
Wed, 18 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Sep 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-17T16:58:29.528Z
Reserved: 2024-07-23T21:02:01.988Z
Link: CVE-2024-7060
Updated: 2024-08-01T21:52:30.379Z
Status : Modified
Published: 2024-07-24T23:15:09.817
Modified: 2024-11-21T09:50:48.840
Link: CVE-2024-7060
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD