CVE-2024-5005

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/462108 Exploit Issue Tracking
https://hackerone.com/reports/2501461 Permissions Required
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

12 Dec 2024, 19:55

Type Values Removed Values Added
First Time Gitlab
Gitlab gitlab
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
References () https://gitlab.com/gitlab-org/gitlab/-/issues/462108 - () https://gitlab.com/gitlab-org/gitlab/-/issues/462108 - Exploit, Issue Tracking
References () https://hackerone.com/reports/2501461 - () https://hackerone.com/reports/2501461 - Permissions Required

Information

Published : 2024-10-11 13:15

Updated : 2024-12-12 19:55


NVD link : CVE-2024-5005

Mitre link : CVE-2024-5005

CVE.ORG link : CVE-2024-5005


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-684

Incorrect Provision of Specified Functionality

NVD-CWE-noinfo