Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48460 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner. |
Solution
Upgrade to versions 17.2.2, 17.1.4, 17.0.6 or above.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/471555 |
|
Fri, 30 Aug 2024 01:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
Fri, 30 Aug 2024 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
Thu, 08 Aug 2024 22:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Aug 2024 19:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific manner. | |
| Title | Exposure of Sensitive Information to an Unauthorized Actor in GitLab | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-08-29T15:05:01.135Z
Reserved: 2024-08-06T09:30:48.539Z
Link: CVE-2024-7554
Updated: 2024-08-08T13:05:52.657Z
Status : Analyzed
Published: 2024-08-08T11:15:13.633
Modified: 2024-08-29T15:42:13.387
Link: CVE-2024-7554
No data.
OpenCVE Enrichment
No data.
EUVD