CVE Vulnerabilities

CVE-2024-9596

Inclusion of Sensitive Information in Source Code

Published: Oct 10, 2024 | Modified: Oct 16, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.

Weakness

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 16.6.0 (including) 17.2.9 (excluding)
Gitlab Gitlab 17.3.0 (including) 17.3.5 (excluding)
Gitlab Gitlab 17.4.0 (including) 17.4.2 (excluding)

Potential Mitigations

References