CVE-2024-5005

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/462108 Exploit Issue Tracking
https://hackerone.com/reports/2501461 Permissions Required
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2024-10-11 13:15

Updated : 2024-12-12 19:55


NVD link : CVE-2024-5005

Mitre link : CVE-2024-5005

CVE.ORG link : CVE-2024-5005


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-684

Incorrect Provision of Specified Functionality

NVD-CWE-noinfo