CVE-2024-8974

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 4, 2024
CWE ID 863
CWE ID 684

Summary

CVE-2024-8974 is a newly disclosed information disclosure vulnerability in GitLab Enterprise Edition (EE) and Community Edition (CE). Affecting versions 15.6 to 17.2.8, 17.3 to 17.3.4, and 17.4 to 17.4.1, this issue enables unauthorized users to access the file path of private projects under specific conditions. Successful exploitation of this vulnerability can lead to significant data exposure. Users are urged to upgrade their GitLab installations to the latest patched versions as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • GitLab
  • GitLab Enterprise Edition

Affected Vendors

  • GitLab Inc.