First published: Fri Mar 28 2025(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >16.0<17.8.6>17.9<17.9.3>17.10<17.10.1 |
Upgrade to versions 17.8.6, 17.9.3, 17.10.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12619 is rated as a high severity vulnerability due to the potential for unauthorized access to internal projects.
To fix CVE-2024-12619, update GitLab CE/EE to versions 17.8.6, 17.9.3, or 17.10.1 or later.
CVE-2024-12619 affects all users of GitLab CE/EE from versions 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1.
CVE-2024-12619 allows internal users to gain unauthorized access to internal projects, posing a significant risk to project confidentiality.
CVE-2024-12619 was disclosed as part of a vulnerability report on GitLab, highlighting security flaws in their software.