CVE-2024-4278

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Sep 26, 2024
Updated: Oct 8, 2024
CWE ID 821

Summary

CVE-2024-4278 is a newly disclosed information disclosure vulnerability in GitLab Enterprise Edition (EE). Affected versions include those from 16.5 to 17.2.8, 17.3 to 17.3.4, and 17.4 to 17.4.1. An attacker with maintainer privileges can exploit this weakness by modifying a specific Dependency Proxy setting, enabling them to gain access to a Dependency Proxy password. This unauthorized access could potentially lead to elevated privileges and unintended exposure of sensitive data. Users are strongly advised to upgrade their GitLab EE instances to the latest patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • GitLab
  • GitLab Enterprise Edition

Affected Vendors

  • GitLab Inc.