Medium severity6.5NVD Advisory· Published Jun 27, 2024· Updated Jun 17, 2026
CVE-2024-3959
CVE-2024-3959
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.7.0,<16.11.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.7.0,<16.11.5
- cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:17.1.0:*:*:*:enterprise:*:*:*
- (no CPE)range: 16.7 - 16.11.4, 17.0 - 17.0.2, 17.1 - 17.1.0
- Range: 16.7 - 16.11.4, 17.0 - 17.0.2, 17.1 - 17.1.0
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/456989nvdBroken Link
- hackerone.com/reports/2456845nvdPermissions Required
News mentions
1- GitLab Critical Patch Release: 17.1.1, 17.0.3, 16.11.5GitLab Security Releases · Jun 26, 2024