First published: Tue Nov 26 2024(Updated: )
An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=17.3.0<17.3.7 | |
GitLab | >=17.3.0<17.3.7 | |
GitLab | >=17.4.0<17.4.4 | |
GitLab | >=17.4.0<17.4.4 | |
GitLab | >=17.5.0<17.5.2 | |
GitLab | >=17.5.0<17.5.2 |
Upgrade to version 17.5.2, 17.4.4, 17.3.7 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10240 is categorized with a medium severity level due to information disclosure risks.
To fix CVE-2024-10240, upgrade GitLab to version 17.3.7, 17.4.4, or 17.5.2 or later.
CVE-2024-10240 affects all GitLab EE versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2.
CVE-2024-10240 allows unauthenticated users to read some information about merge requests in private repositories.
CVE-2024-10240 was disclosed in November 2024 and has potential impacts on user data security.