An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 |
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2024-06-26T23:31:35.425Z
Updated: 2024-08-30T13:24:42.967Z
Reserved: 2024-03-29T23:30:45.826Z
Link: CVE-2024-3115
Vulnrichment
Updated: 2024-08-01T19:32:42.612Z
NVD
Status : Modified
Published: 2024-06-27T00:15:11.190
Modified: 2024-11-21T09:28:56.000
Link: CVE-2024-3115
Redhat
No data.