CVE-2024-5005: Incorrect Provision of Specified Functionality in GitLab
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.
Other sources
An issue has been discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2. It was possible for guest users to disclose project templates using the API. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, 4.3). It is now mitigated in the latest release and is assigned CVE-2024-5005.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5005?
CVE-2024-5005 is a medium severity vulnerability that allows guest users to disclose project templates through the API.
What versions are affected by CVE-2024-5005?
CVE-2024-5005 affects GitLab versions starting from 11.4 before 17.2.9, from 17.3 before 17.3.5, and from 17.4 before 17.4.2.
How do I fix CVE-2024-5005?
To fix CVE-2024-5005, upgrade your GitLab instance to versions 17.2.9, 17.3.5, or 17.4.2 or later.
What impact does CVE-2024-5005 have?
The impact of CVE-2024-5005 is that unauthorized guest users can access and disclose sensitive project templates.
Who is vulnerable to CVE-2024-5005?
All users of GitLab EE/CE versions in the specified ranges are vulnerable to CVE-2024-5005.