First published: Mon Mar 03 2025(Updated: )
A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=16.2<17.7.6>=17.8<17.8.4>=17.9<17.9.1 |
Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10925 is classified as a medium severity vulnerability.
CVE-2024-10925 affects GitLab-EE versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1.
To fix CVE-2024-10925, you should upgrade to GitLab-EE version 17.7.6, 17.8.4, or 17.9.1 or later.
CVE-2024-10925 allows a Guest user to read sensitive Security policy YAML files.
CVE-2024-10925 could lead to exposure of sensitive security information to unauthorized users.