First published: Wed Feb 05 2025(Updated: )
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | >=14.0>=16.0<16.9.7>=16.10<16.10.5>=16.11<16.11.2 |
Upgrade to versions 16.9.7, 16.10.5, 16.11.2 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3976 has a medium severity level due to the risk of confidential information disclosure.
To fix CVE-2024-3976, update GitLab CE/EE to version 16.9.7 or later, or any version newer than 16.10.5 or 16.11.2.
CVE-2024-3976 affects all GitLab CE/EE versions starting from 14.0 up to and including 16.9.6, 16.10.4, and 16.11.1.
CVE-2024-3976 allows unauthorized disclosure of the confidential issues title and description through the user interface.
CVE-2024-3976 is not classified as critical but poses a significant privacy risk to users.