CVE-2024-7586: Insertion of Sensitive Information into Log File in GitLab
An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-7586?
CVE-2024-7586 has been classified with a high severity due to the potential exposure of authentication credentials.
How do I fix CVE-2024-7586?
To fix CVE-2024-7586, upgrade GitLab EE to version 17.0.6, 17.1.4, or 17.2.2 or later.
What versions of GitLab EE are affected by CVE-2024-7586?
CVE-2024-7586 affects GitLab EE versions starting from 17.0 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2.
What is the impact of CVE-2024-7586?
The impact of CVE-2024-7586 includes the possible leakage of authentication credentials in webhook deletion audit logs.
Is there a workaround for CVE-2024-7586?
No official workaround is provided for CVE-2024-7586; upgrading to the patched versions is the recommended solution.