CVE-2024-5067: Exposure of Sensitive Information to an Unauthorized Actor in GitLab
An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles. This is a medium severity issue (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N , 4.4). It is now mitigated in the latest release and is assigned CVE-2024-5067.
Other sources
An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5067?
CVE-2024-5067 is considered a medium severity vulnerability due to the potential for disclosure of sensitive project-level analytics.
How do I fix CVE-2024-5067?
To fix CVE-2024-5067, upgrade GitLab to version 17.0.5 or later, 17.1.3 or later, or 17.2.1 or later.
Who is affected by CVE-2024-5067?
CVE-2024-5067 affects all users of GitLab EE versions from 16.11 up to but not including 17.0.5, from 17.1 up to but not including 17.1.3, and from 17.2 up to but not including 17.2.1.
What are the potential impacts of CVE-2024-5067?
The potential impacts of CVE-2024-5067 include unauthorized access to leaked project-level analytics settings by group members with Developer or higher roles.
Is CVE-2024-5067 exploitable remotely?
Yes, CVE-2024-5067 can be exploited remotely by users with the appropriate access levels within GitLab.