CVE-2024-7060

LOW

Gitlab < 17.0.5 - Information Disclosure

Title source: rule

Description

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

Scores

CVSS v3 2.6
EPSS 0.0006
EPSS Percentile 19.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (2)

gitlab/gitlab < 17.0.5
gitlab/gitlab < 17.0.5

Timeline

Published Jul 24, 2024
Tracked Since Feb 18, 2026