CVE-2024-2191

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/444655 - Broken Link () https://gitlab.com/gitlab-org/gitlab/-/issues/444655 - Broken Link
References () https://hackerone.com/reports/2357370 - Permissions Required () https://hackerone.com/reports/2357370 - Permissions Required

28 Jun 2024, 13:23

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
CWE NVD-CWE-noinfo
First Time Gitlab
Gitlab gitlab
References () https://gitlab.com/gitlab-org/gitlab/-/issues/444655 - () https://gitlab.com/gitlab-org/gitlab/-/issues/444655 - Broken Link
References () https://hackerone.com/reports/2357370 - () https://hackerone.com/reports/2357370 - Permissions Required

27 Jun 2024, 12:47

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en GitLab CE/EE que afecta a todas las versiones desde la 16.9 anterior a la 16.11.5, desde la 17.0 anterior a la 17.0.3 y desde la 17.1 anterior a la 17.1.1, lo que permite que el título de la solicitud de fusión sea visible públicamente a pesar de estar establecido solo para miembros del proyecto.

27 Jun 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 00:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2191

Mitre link : CVE-2024-2191

CVE.ORG link : CVE-2024-2191


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo