First published: Thu Dec 12 2024(Updated: )
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >=11.0<17.4.6>=17.5<17.5.4>=17.6<17.6.2 |
Upgrade to versions 17.4.6, 17.5.4, 17.6.2 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12292 has a high severity rating due to the potential exposure of sensitive information through GraphQL logs.
To fix CVE-2024-12292, upgrade GitLab CE/EE to versions 17.4.6, 17.5.4, or 17.6.2 or later.
CVE-2024-12292 affects GitLab CE/EE versions starting from 11.0 prior to 17.4.6, and versions starting from 17.5 prior to 17.5.4 and from 17.6 prior to 17.6.2.
CVE-2024-12292 is a vulnerability related to the exposure of sensitive information via GraphQL mutations.
Yes, CVE-2024-12292 can potentially lead to data breaches if sensitive information retained in GraphQL logs is accessed by unauthorized users.