CVE-2024-7060Sensitive Information Exposure in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 80.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24
Latest updateJul 25

Description

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDgitlab/gitlab15.417.0.5+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-pqgh-rchr-9hg3: An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 152024-07-25

📋Vendor Advisories

2
GitLab
CVE-2024-7060: An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.2024-07-24
Debian
CVE-2024-7060: gitlab - An information disclosure vulnerability in GitLab CE/EE in project/group exports...2024