Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/457912 |
|
History
Wed, 18 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Aug 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-653 |
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published: 2024-06-26T23:30:40.557Z
Updated: 2024-09-17T17:03:09.769Z
Reserved: 2024-06-25T13:25:40.311Z
Link: CVE-2024-6323
Updated: 2024-08-01T21:33:05.449Z
Status : Modified
Published: 2024-06-27T00:15:13.130
Modified: 2024-11-21T09:49:25.880
Link: CVE-2024-6323
No data.