First published: Wed Jul 24 2024(Updated: )
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=15.6<17.0.5 | |
GitLab | >=15.6<17.0.5 | |
GitLab | >=17.1<17.1.3 | |
GitLab | >=17.1<17.1.3 | |
GitLab | >=17.2<17.2.1 | |
GitLab | >=17.2<17.2.1 |
Upgrade to versions 17.0.5, 17.1.3, 17.2.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7091 is classified as a medium severity vulnerability due to its potential to disclose limited information to unauthorized users.
To fix CVE-2024-7091, upgrade your GitLab installation to version 17.0.5 or later, version 17.1.3 or later, or version 17.2.1 or later.
CVE-2024-7091 affects GitLab CE/EE versions from 15.6 up to but not including 17.0.5, from 17.1 up to but not including 17.1.3, and from 17.2 up to but not including 17.2.1.
CVE-2024-7091 may allow unauthorized users to access limited information about an exported group or project.
Currently, there is no known workaround for CVE-2024-7091; upgrading to the patched versions is the recommended action.