CVE-2024-7091 — Sensitive Information Exposure in Gitlab
Severity
5.0MEDIUMNVD
OSV5.3
EPSS
0.1%
top 77.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 24
Latest updateNov 21
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 3.1 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2024-7091: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting fr↗2024-07-24
Debian▶
CVE-2024-7091: gitlab - An issue was discovered in GitLab CE/EE affecting all versions starting from 15....↗2024