CVE-2024-2191

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

28 Jun 2024, 13:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://gitlab.com/gitlab-org/gitlab/-/issues/444655 - () https://gitlab.com/gitlab-org/gitlab/-/issues/444655 - Broken Link
References () https://hackerone.com/reports/2357370 - () https://hackerone.com/reports/2357370 - Permissions Required
First Time Gitlab gitlab
Gitlab
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
CWE NVD-CWE-noinfo

27 Jun 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 00:15

Updated : 2024-06-28 13:23


NVD link : CVE-2024-2191

Mitre link : CVE-2024-2191


JSON object : View

Products Affected

gitlab

  • gitlab