CVE-2024-7060: Exposure of Sensitive Information to an Unauthorized Actor in GitLab
An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7060?
CVE-2024-7060 is classified as a medium severity information disclosure vulnerability in GitLab.
How do I fix CVE-2024-7060?
To fix CVE-2024-7060, upgrade your GitLab instance to version 17.0.5 or later, 17.1.3 or later, or 17.2.1 or later.
What versions of GitLab are affected by CVE-2024-7060?
CVE-2024-7060 affects all GitLab CE/EE versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1.
What type of vulnerability is CVE-2024-7060?
CVE-2024-7060 is an information disclosure vulnerability that allows unauthorized users to view sensitive project or group export data.
Can CVE-2024-7060 affect both GitLab CE and EE?
Yes, CVE-2024-7060 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) across the specified vulnerable versions.