First published: Thu Dec 12 2024(Updated: )
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Enterprise Edition | >=14.3<17.4.6>=17.5<17.5.4>=17.6<17.6.2 |
Upgrade to versions 17.4.6, 17.5.4, 17.6.2 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10043 has a high severity rating due to its potential to expose confidential incident titles to unauthorized users.
To fix CVE-2024-10043, upgrade your GitLab EE installation to version 17.5.4 or later, or to version 17.6.2 or later.
CVE-2024-10043 affects GitLab EE versions from 14.3 up to but not including 17.4.6, from 17.5 up to but not including 17.5.4, and from 17.6 up to but not including 17.6.2.
Group users within affected GitLab EE versions can view confidential incident titles through the Wiki History Diff feature.
If you cannot upgrade, consider implementing access controls or limiting group user permissions to mitigate the risks associated with CVE-2024-10043.