An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.
History

Wed, 05 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 03:15:00 +0000

Type Values Removed Values Added
Description An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.
Title Insufficient Granularity of Access Control in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-1220
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2025-02-05T20:14:21.196Z

Reserved: 2024-11-27T20:02:05.948Z

Link: CVE-2024-11931

cve-icon Vulnrichment

Updated: 2025-02-05T20:14:17.026Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-24T03:15:06.590

Modified: 2025-02-05T21:15:22.473

Link: CVE-2024-11931

cve-icon Redhat

No data.