CVE-2024-3976: Missing Authorization in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3976?
CVE-2024-3976 has a medium severity level due to the risk of confidential information disclosure.
How do I fix CVE-2024-3976?
To fix CVE-2024-3976, update GitLab CE/EE to version 16.9.7 or later, or any version newer than 16.10.5 or 16.11.2.
What versions are affected by CVE-2024-3976?
CVE-2024-3976 affects all GitLab CE/EE versions starting from 14.0 up to and including 16.9.6, 16.10.4, and 16.11.1.
What kind of data can be disclosed due to CVE-2024-3976?
CVE-2024-3976 allows unauthorized disclosure of the confidential issues title and description through the user interface.
Is CVE-2024-3976 a critical vulnerability?
CVE-2024-3976 is not classified as critical but poses a significant privacy risk to users.