CVE-2024-3115: Exposure of Sensitive Information to an Unauthorized Actor in GitLab
An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3115?
CVE-2024-3115 is categorized as a moderate severity vulnerability.
How do I fix CVE-2024-3115?
To address CVE-2024-3115, upgrade to GitLab versions 16.11.5, 17.0.3, or 17.1.1 or later.
What systems are affected by CVE-2024-3115?
CVE-2024-3115 affects GitLab versions from 16.0 to before 16.11.5, 17.0 to before 17.0.3, and specifically 17.1.0.
What type of access does CVE-2024-3115 allow an attacker?
CVE-2024-3115 allows an attacker to access issues and epics without having an SSO session using Duo Chat.
What should I do if I cannot upgrade to the patched versions for CVE-2024-3115?
If an upgrade is not possible, review access controls and consider temporarily disabling affected features until a patch can be applied.