Sensitive Information Retention in GitLab GraphQL Logs

CVE-2024-12292

4MEDIUM

Key Information

Vendor
Gitlab
Status
Gitlab
Vendor
CVE Published:
12 December 2024

Summary

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

Affected Version(s)

GitLab < 17.4.6

GitLab < 17.5.4

GitLab < 17.6.2

Refferences

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

This issue was discovered internally by GitLab team member [Radamanthus Batnag](https://gitlab.com/radbatnag).
.