An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/493355 |
|
History
Wed, 16 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
Thu, 10 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Oct 2024 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance. | |
| Title | Inclusion of Sensitive Information in Source Code in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-540 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published: 2024-10-10T10:02:01.165Z
Updated: 2024-10-10T13:55:09.715Z
Reserved: 2024-10-07T17:30:34.890Z
Link: CVE-2024-9596
Updated: 2024-10-10T13:55:00.525Z
Status : Analyzed
Published: 2024-10-10T10:15:08.563
Modified: 2024-10-16T17:00:19.787
Link: CVE-2024-9596
No data.