First published: Thu Apr 24 2025(Updated: )
An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Enterprise Edition | >17.7<17.9.7>17.10<17.10.5>17.11<17.11.1 |
Upgrade to versions 17.9.7, 17.10.5, 17.11.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12244 has been classified as a high severity vulnerability due to its potential impact on access controls.
To fix CVE-2024-12244, upgrade GitLab EE to version 17.9.7, 17.10.5, or 17.11.1 or later.
CVE-2024-12244 affects all versions of GitLab EE from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.
CVE-2024-12244 represents an issue with access controls that may allow unauthorized users to view restricted project information.
No, CVE-2024-12244 has been addressed in the subsequent versions and is not present in versions 17.9.7, 17.10.5, or 17.11.1 onwards.