CVE-2024-12292: Insertion of Sensitive Information into Log File in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 before 17.4.6, starting from 17.5 before 17.5.4, and starting from 17.6 before 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs. This is a medium severity issue (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, 4.0). It is now mitigated in the latest release and is assigned CVE-2024-12292.
Other sources
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.
— MITRE
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-12292?
CVE-2024-12292 has a high severity rating due to the potential exposure of sensitive information through GraphQL logs.
How do I fix CVE-2024-12292?
To fix CVE-2024-12292, upgrade GitLab CE/EE to versions 17.4.6, 17.5.4, or 17.6.2 or later.
What versions of GitLab are affected by CVE-2024-12292?
CVE-2024-12292 affects GitLab CE/EE versions starting from 11.0 prior to 17.4.6, and versions starting from 17.5 prior to 17.5.4 and from 17.6 prior to 17.6.2.
What type of vulnerability is CVE-2024-12292?
CVE-2024-12292 is a vulnerability related to the exposure of sensitive information via GraphQL mutations.
Can CVE-2024-12292 lead to data breaches?
Yes, CVE-2024-12292 can potentially lead to data breaches if sensitive information retained in GraphQL logs is accessed by unauthorized users.