CVE Vulnerabilities

CVE-2024-5005

Incorrect Provision of Specified Functionality

Published: Oct 11, 2024 | Modified: Oct 15, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Affected Software

Name Vendor Start Version End Version
Gitlab Ubuntu esm-apps/xenial *

Potential Mitigations

References