Medium severity5.5NVD Advisory· Published Sep 26, 2024· Updated Jun 17, 2026
CVE-2024-4278
CVE-2024-4278
Description
An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: >=16.5 <17.2.8, >=17.3 <17.3.4, >=17.4 <17.4.1
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.5.0,<17.2.8
- cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.5
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/458484nvdBroken Link
- hackerone.com/reports/2466205nvdPermissions Required
News mentions
1- GitLab Patch Release: 17.4.1, 17.3.4, 17.2.8GitLab Security Releases · Sep 25, 2024