An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Aug 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:enterprise:*:*:* |
Wed, 05 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 24 Jan 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint. | |
| Title | Insufficient Granularity of Access Control in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-1220 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published: 2025-01-24T03:02:16.074Z
Updated: 2025-02-05T20:14:21.196Z
Reserved: 2024-11-27T20:02:05.948Z
Link: CVE-2024-11931
Updated: 2025-02-05T20:14:17.026Z
Status : Analyzed
Published: 2025-01-24T03:15:06.590
Modified: 2025-08-05T19:57:08.360
Link: CVE-2024-11931
No data.