Low severity2.6NVD Advisory· Published Sep 26, 2024· Updated Jun 17, 2026
CVE-2024-8974
CVE-2024-8974
Description
Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.6
- (no CPE)range: from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.6.0,<17.2.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.6.0,<17.2.8
- cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:17.4.0:*:*:*:enterprise:*:*:*
- Range: from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1
Patches
Vulnerability mechanics
References
1- gitlab.com/gitlab-org/gitlab/-/issues/482843nvdBroken Link
News mentions
1- GitLab Patch Release: 17.4.1, 17.3.4, 17.2.8GitLab Security Releases · Sep 25, 2024