An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 05 Feb 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 05 Feb 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users. | |
Title | Missing Authorization in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-02-05T20:12:12.955Z
Reserved: 2024-04-19T08:02:17.288Z
Link: CVE-2024-3976

Updated: 2025-02-05T20:12:03.550Z

Status : Received
Published: 2025-02-05T12:15:27.627
Modified: 2025-02-05T20:15:44.750
Link: CVE-2024-3976

No data.