4.3

CVE-2024-8974

Incorrect Provision of Specified Functionality in GitLab

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 15.6.0 < 17.2.8
Gitlab ≫ GitLab SwEdition enterprise Version >= 15.6.0 < 17.2.8
Gitlab ≫ GitLab SwEdition community Version >= 17.3.0 < 17.3.4
Gitlab ≫ GitLab SwEdition enterprise Version >= 17.3.0 < 17.3.4
Gitlab ≫ GitLab Version 17.4.0 SwEdition community
Gitlab ≫ GitLab Version 17.4.0 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.194
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
cve@gitlab.com 2.6 1.2 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
CWE-684 Incorrect Provision of Specified Functionality

The code does not function according to its published specifications, potentially leading to incorrect usage.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://gitlab.com/gitlab-org/gitlab/-/issues/482843
Broken Link