216.73.216.226

CVE-2024-4278

· Published 26/09/2024 07:15 · Modified 08/10/2024 19:51

Labels: CVE-2024-4278 2024-09-26CVE-2024-4278CWE-662CWE-821NVD-CWE-Other[email protected]

Essential information

Published
26/09/2024 07:15
Modified
08/10/2024 19:51
Author
Creator
CVSS
2.7 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*

References