CVE-2024-4278
Last modified
CVE-2024-4278 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 16.5.0, < 17.2.8 |
| Gitlab | Gitlab | >= 17.3.0, < 17.3.4 |
| Gitlab | Gitlab | 17.4.0 |
References
- https://hackerone.com/reports/2466205Permissions Required
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4278?
How severe is CVE-2024-4278?
How do I fix CVE-2024-4278?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-42774An Incorrect Access Control vulnerability was found in /admi…7.5
- CVE-2024-42775An Incorrect Access Control vulnerability was found in /admi…9.1
- CVE-2024-42776Kashipara Hotel Management System v1.0 is vulnerable to Inco…7.2
- CVE-2024-42777An Unrestricted file upload vulnerability was found in "/mus…9.8
- CVE-2024-42778An Unrestricted file upload vulnerability was found in "/mus…8.8
- CVE-2024-42779An Unrestricted file upload vulnerability was found in "/mus…8.8
- CVE-2024-42780An Unrestricted file upload vulnerability was found in "/mus…8.8
- CVE-2024-42781A SQL injection vulnerability in "/music/ajax.php?action=log…9.8
- CVE-2024-42782A SQL injection vulnerability in "/music/ajax.php?action=fin…9.8
- CVE-2024-42783Kashipara Music Management System v1.0 is vulnerable to SQL …9.8
- CVE-2024-42784A SQL injection vulnerability in "/music/controller.php?page…9.8
- CVE-2024-42785A SQL injection vulnerability in /music/index.php?page=view_…8.8
Are you affected by CVE-2024-4278?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
