An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.
Metrics
Affected Vendors & Products
References
History
Fri, 08 Aug 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:17.11.0:*:*:*:enterprise:*:*:* |
Thu, 24 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Apr 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1. | |
Title | Missing Authorization in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published: 2025-04-24T07:31:11.125Z
Updated: 2025-04-24T15:23:11.499Z
Reserved: 2024-12-05T14:30:37.459Z
Link: CVE-2024-12244

Updated: 2025-04-24T13:48:21.115Z

Status : Analyzed
Published: 2025-04-24T08:15:14.020
Modified: 2025-08-08T16:54:18.123
Link: CVE-2024-12244

No data.