CVE-2024-2191: Improper Access Control in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2191?
CVE-2024-2191 has been classified with a high severity due to its potential exposure of sensitive information.
How do I fix CVE-2024-2191?
To resolve CVE-2024-2191, upgrade GitLab to version 16.11.5 or 17.0.3 or higher.
Who is affected by CVE-2024-2191?
CVE-2024-2191 affects all versions of GitLab CE and EE starting from 16.9 to prior 16.11.5, 17.0 to prior 17.0.3, and 17.1 to prior 17.1.1.
What does CVE-2024-2191 exploit?
CVE-2024-2191 allows merge request titles to be publicly visible despite being configured for project members only.
When was CVE-2024-2191 discovered?
CVE-2024-2191 was discovered recently, affecting specific versions of GitLab released in 2023.