CVE-2024-2191

MEDIUM

GitLab CE/EE <16.11.5-17.1.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

References (2)

Core 2
Core References
Broken Link issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/444655
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/2357370

Scores

CVSS v3 5.3
EPSS 0.0018
EPSS Percentile 39.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
gitlab/gitlab 17.1.0 (2 CPE variants)
gitlab/gitlab 16.9.0 - 16.11.5 (2 CPE variants)
Published Jun 27, 2024
Tracked Since Feb 18, 2026