CVE Vulnerabilities

CVE-2024-5005

Incorrect Provision of Specified Functionality

Published: Oct 11, 2024 | Modified: Dec 12, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab11.4.0 (including)17.2.9 (excluding)
GitlabGitlab17.3.0 (including)17.3.5 (excluding)
GitlabGitlab17.4.0 (including)17.4.2 (excluding)
GitlabUbuntuesm-apps/xenial*

Potential Mitigations

References