VYPR
Low severity2.6NVD Advisory· Published Sep 26, 2024· Updated Jun 17, 2026

CVE-2024-8974

CVE-2024-8974

Description

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

Affected products

8
  • GitLab Inc./GitLabv56 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.6
    • (no CPE)range: from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.6.0,<17.2.8
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.6.0,<17.2.8
    • cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:community:*:*:*
    • cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*
  • osv-coords
    Range: >= 15.6.0, < 17.2.8
  • Range: from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1

Patches

Vulnerability mechanics

References

1

News mentions

1