CVE-2024-4472

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, where dependency proxy credentials are retained in graphql Logs.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

18 Sep 2024, 19:16

Type Values Removed Values Added
CWE CWE-532
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Gitlab gitlab
Gitlab
References () https://hackerone.com/reports/2477062 - () https://hackerone.com/reports/2477062 - Permissions Required
References () https://gitlab.com/gitlab-org/gitlab/-/issues/460289 - () https://gitlab.com/gitlab-org/gitlab/-/issues/460289 - Broken Link

12 Sep 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-12 19:15

Updated : 2024-09-18 19:16


NVD link : CVE-2024-4472

Mitre link : CVE-2024-4472


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-532

Insertion of Sensitive Information into Log File