CVE-2024-4472

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, where dependency proxy credentials are retained in graphql Logs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 09:42

Type Values Removed Values Added
References
  • () https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/ -
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 4.0

18 Sep 2024, 19:16

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.5 anterior a la 17.1.7, desde la 17.2 anterior a la 17.2.5 y desde la 17.3 anterior a la 17.3.2, donde las credenciales del proxy de dependencia se conservan en los registros de graphql.
References () https://gitlab.com/gitlab-org/gitlab/-/issues/460289 - () https://gitlab.com/gitlab-org/gitlab/-/issues/460289 - Broken Link
References () https://hackerone.com/reports/2477062 - () https://hackerone.com/reports/2477062 - Permissions Required
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
CVSS v2 : unknown
v3 : 4.0
v2 : unknown
v3 : 5.5
First Time Gitlab
Gitlab gitlab

12 Sep 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-12 19:15

Updated : 2024-11-21 09:42


NVD link : CVE-2024-4472

Mitre link : CVE-2024-4472

CVE.ORG link : CVE-2024-4472


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-532

Insertion of Sensitive Information into Log File