First published: Wed Jun 26 2024(Updated: )
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=16.9.0<16.11.5 | |
GitLab | >=16.9.0<16.11.5 | |
GitLab | >=17.0.0<17.0.3 | |
GitLab | >=17.0.0<17.0.3 | |
GitLab | =17.1.0 | |
GitLab | =17.1.0 |
Upgrade to versions 17.1.1, 17.0.3, 16.11.5 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2191 has been classified with a high severity due to its potential exposure of sensitive information.
To resolve CVE-2024-2191, upgrade GitLab to version 16.11.5 or 17.0.3 or higher.
CVE-2024-2191 affects all versions of GitLab CE and EE starting from 16.9 to prior 16.11.5, 17.0 to prior 17.0.3, and 17.1 to prior 17.1.1.
CVE-2024-2191 allows merge request titles to be publicly visible despite being configured for project members only.
CVE-2024-2191 was discovered recently, affecting specific versions of GitLab released in 2023.