CVE Vulnerabilities

CVE-2024-6389

Published: Sep 12, 2024 | Modified: Sep 14, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permissions.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 17.0.0 (including) 17.1.7 (excluding)
Gitlab Gitlab 17.2.0 (including) 17.2.5 (excluding)
Gitlab Gitlab 17.3.0 (including) 17.3.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu upstream *

References