Sensitive Information Retention in GitLab GraphQL Logs
CVE-2024-12292
4MEDIUM
Summary
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.
Affected Version(s)
GitLab < 17.4.6
GitLab < 17.5.4
GitLab < 17.6.2
Refferences
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
This issue was discovered internally by GitLab team member [Radamanthus Batnag](https://gitlab.com/radbatnag).