CVE-2024-7057

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 09:50

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/458501 - Broken Link () https://gitlab.com/gitlab-org/gitlab/-/issues/458501 - Broken Link
References () https://hackerone.com/reports/2475135 - Permissions Required () https://hackerone.com/reports/2475135 - Permissions Required

05 Sep 2024, 17:33

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/458501 - () https://gitlab.com/gitlab-org/gitlab/-/issues/458501 - Broken Link
References () https://hackerone.com/reports/2475135 - () https://hackerone.com/reports/2475135 - Permissions Required
First Time Gitlab gitlab
Gitlab
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Summary
  • (es) Una vulnerabilidad de divulgación de información en GitLab CE/EE que afecta a todas las versiones desde la 16.7 anterior a la 17.0.5, desde la 17.1 anterior a la 17.1.3 y desde la 17.2 anterior a la 17.2.1, donde los artefactos del trabajo pueden exponerse de manera inapropiada a usuarios que carecen de la nivel de autorización adecuado.

25 Jul 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-25 01:15

Updated : 2024-11-21 09:50


NVD link : CVE-2024-7057

Mitre link : CVE-2024-7057

CVE.ORG link : CVE-2024-7057


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo