VDB

CVE-2024-10240

CVE-2024-10240 PUBLISHED

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

EPSS 0.18% · 39.6th percentile

Risk Scores

EPSS Score
0.18%
39.6th percentile

Affected Products

VendorProductVersions
Bitnamigitlab17.5.0, 17.4.0, 17.3.0
Bitnamigitlab17.3.0, 17.4.0, 17.5.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Nov 12, 2024 CVE Published
  • Nov 13, 2024 PoC Published
  • Nov 26, 2024 PoC Published
  • Nov 27, 2024 EPSS Score
  • Dec 15, 2024 EPSS Score
  • Dec 31, 2024 Coalition ESS Score
  • Jan 1, 2025 EPSS Score
  • Jan 19, 2025 EPSS Score
  • Feb 5, 2025 EPSS Score
  • Feb 6, 2025 CVE Updated
  • Feb 22, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›