CVE-2024-12380

MEDIUM

GitLab 11.5-17.7.6, 17.8-17.8.4, 17.9-17.9.1 - Sensitive Information Exposure in Repository Mirroring Settings

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

References (2)

Core 2
Core References
Broken Link issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/508557
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/2868951

Scores

CVSS v3 4.4
EPSS 0.0053
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
gitlab/gitlab 11.5.0 - 17.7.7 (2 CPE variants)
Published Mar 13, 2025
Tracked Since Feb 18, 2026