CVE-2024-4278
CVSS 3.1 Score 2.7 of 10 (low)
Details
Summary
CVE-2024-4278 is a newly disclosed information disclosure vulnerability in GitLab Enterprise Edition (EE). Affected versions include those from 16.5 to 17.2.8, 17.3 to 17.3.4, and 17.4 to 17.4.1. An attacker with maintainer privileges can exploit this weakness by modifying a specific Dependency Proxy setting, enabling them to gain access to a Dependency Proxy password. This unauthorized access could potentially lead to elevated privileges and unintended exposure of sensitive data. Users are strongly advised to upgrade their GitLab EE instances to the latest patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
- GitLab Enterprise Edition
Affected Vendors
- GitLab Inc.