Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49516 | Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project." |
Solution
Upgrade to version 17.4.1, 17.3.4, 17.2.8.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/482843 |
|
Sun, 13 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 05 Oct 2024 03:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:* |
Sat, 28 Sep 2024 01:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Sep 2024 08:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project." | |
| Title | Incorrect Provision of Specified Functionality in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-684 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-27T15:46:48.041Z
Reserved: 2024-09-18T14:01:58.766Z
Link: CVE-2024-8974
Updated: 2024-09-27T15:46:42.955Z
Status : Analyzed
Published: 2024-09-26T23:15:03.083
Modified: 2024-10-04T17:30:18.803
Link: CVE-2024-8974
No data.
OpenCVE Enrichment
No data.
EUVD