An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.
History

Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 07:45:00 +0000

Type Values Removed Values Added
Description An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.
Title Missing Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-862
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2025-04-24T07:31:11.125Z

Updated: 2025-04-24T15:23:11.499Z

Reserved: 2024-12-05T14:30:37.459Z

Link: CVE-2024-12244

cve-icon Vulnrichment

Updated: 2025-04-24T13:48:21.115Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-24T08:15:14.020

Modified: 2025-04-29T13:52:47.470

Link: CVE-2024-12244

cve-icon Redhat

No data.