CVE Vulnerabilities

CVE-2024-7060

Published: Jul 24, 2024 | Modified: Sep 05, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 15.4 (including) 17.0.5 (excluding)
Gitlab Gitlab 17.1 (including) 17.1.3 (excluding)
Gitlab Gitlab 17.2 (including) 17.2.1 (excluding)

References