First published: Thu Sep 26 2024(Updated: )
Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=15.6.0<17.2.8 | |
GitLab | >=15.6.0<17.2.8 | |
GitLab | >=17.3.0<17.3.4 | |
GitLab | >=17.3.0<17.3.4 | |
GitLab | =17.4.0 | |
GitLab | =17.4.0 |
Upgrade to version 17.4.1, 17.3.4, 17.2.8.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8974 has been classified as a moderate severity vulnerability due to potential information disclosure.
To fix CVE-2024-8974, you should upgrade GitLab to version 17.2.8, 17.3.4, or 17.4.1 or later.
CVE-2024-8974 affects all versions of GitLab from 15.6 to versions prior to 17.2.8, 17.3.4, and 17.4.1.
CVE-2024-8974 allows for information disclosure where unauthorized users may obtain the path of a private project.
Yes, the impact of CVE-2024-8974 occurs under specific conditions that allow unauthorized access to project paths.