An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 |
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |

Status: PUBLISHED
Assigner: GitLab
Published: 2024-06-26T23:31:35.425Z
Updated: 2024-08-30T13:24:42.967Z
Reserved: 2024-03-29T23:30:45.826Z
Link: CVE-2024-3115

Updated: 2024-08-01T19:32:42.612Z

Status : Modified
Published: 2024-06-27T00:15:11.190
Modified: 2024-11-21T09:28:56.000
Link: CVE-2024-3115

No data.