CVE-2024-8974
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Sep 26, 2024
Updated: Oct 4, 2024
CWE ID 863
CWE ID 684
Summary
CVE-2024-8974 is a newly disclosed information disclosure vulnerability in GitLab Enterprise Edition (EE) and Community Edition (CE). Affecting versions 15.6 to 17.2.8, 17.3 to 17.3.4, and 17.4 to 17.4.1, this issue enables unauthorized users to access the file path of private projects under specific conditions. Successful exploitation of this vulnerability can lead to significant data exposure. Users are urged to upgrade their GitLab installations to the latest patched versions as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
- GitLab Enterprise Edition
Affected Vendors
- GitLab Inc.