Vulnerability in GitLab EE Could Leak Project-Level Analytics to Group Members
CVE-2024-5067
4.9MEDIUM
Summary
An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.
Affected Version(s)
GitLab < 17.0.5
GitLab < 17.1.3
GitLab < 17.2.1
Refferences
https://gitlab.com/gitlab-org/gitlab/-/issues/458504
issue-trackingpermissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/462427
issue-trackingpermissions-required
https://hackerone.com/reports/2462303
technical-descriptionexploitpermissions-required
https://hackerone.com/reports/2502047
technical-descriptionexploitpermissions-required
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Thanks [yvvdwf](https://hackerone.com/yvvdwf) and [zebraman](https://hackerone.com/zebraman) for reporting this vulnerability through our HackerOne bug bounty program