216.73.216.6

CVE-2024-5005

· Published 11/10/2024 13:15 · Modified 15/10/2024 12:58

Labels: CVE-2024-5005 2024-10-11CVE-2024-5005CWE-684[email protected]

Essential information

Published
11/10/2024 13:15
Modified
15/10/2024 12:58
Author
Creator
CVSS
4.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References