2024-09-12 18:03:19 +00:00
{
"id" : "CVE-2024-5435" ,
"sourceIdentifier" : "cve@gitlab.com" ,
"published" : "2024-09-12T17:15:05.147" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T09:47:40.767" ,
"vulnStatus" : "Modified" ,
2024-09-12 18:03:19 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration."
2024-09-14 16:03:15 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones desde la 15.10 hasta la 17.1.7, todas las versiones desde la 17.2 hasta la 17.2.5 y todas las versiones desde la 17.3 hasta la 17.3.2, que revelar\u00e1n la contrase\u00f1a del usuario desde la configuraci\u00f3n del espejo del repositorio."
2024-09-12 18:03:19 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-09-14 16:03:15 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
2024-09-14 16:03:15 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N" ,
"baseScore" : 4.5 ,
"baseSeverity" : "MEDIUM" ,
2024-09-14 16:03:15 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
2024-12-08 03:06:42 +00:00
"privilegesRequired" : "HIGH" ,
"userInteraction" : "REQUIRED" ,
2024-09-14 16:03:15 +00:00
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-09-14 16:03:15 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 0.9 ,
2024-09-14 16:03:15 +00:00
"impactScore" : 3.6
} ,
2024-09-12 18:03:19 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-09-12 18:03:19 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
2024-09-12 18:03:19 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
2024-12-08 03:06:42 +00:00
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
2024-09-12 18:03:19 +00:00
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-09-12 18:03:19 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 2.8 ,
2024-09-12 18:03:19 +00:00
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
2024-09-14 16:03:15 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
2024-09-14 16:03:15 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-209"
}
]
} ,
2024-09-12 18:03:19 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-09-12 18:03:19 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-209"
}
]
}
] ,
2024-09-14 16:03:15 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*" ,
"versionStartIncluding" : "15.10.0" ,
"versionEndExcluding" : "17.1.7" ,
"matchCriteriaId" : "ABF7770C-12E5-496B-8D5F-F6E55E610AA8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*" ,
"versionStartIncluding" : "15.10.0" ,
"versionEndExcluding" : "17.1.7" ,
"matchCriteriaId" : "A9EB56F1-6DB6-45C7-BD1B-B7B28A15B291"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*" ,
"versionStartIncluding" : "17.2.0" ,
"versionEndExcluding" : "17.2.5" ,
"matchCriteriaId" : "9DE9BFF3-C056-4146-A762-E34D60E10EDE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*" ,
"versionStartIncluding" : "17.2.0" ,
"versionEndExcluding" : "17.2.5" ,
"matchCriteriaId" : "1F428DA1-FB1C-4B14-A1E1-65177E7F4B10"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*" ,
"versionStartIncluding" : "17.3.0" ,
"versionEndExcluding" : "17.3.2" ,
"matchCriteriaId" : "D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*" ,
"versionStartIncluding" : "17.3.0" ,
"versionEndExcluding" : "17.3.2" ,
"matchCriteriaId" : "145E52CC-F503-446E-A760-1C01753DA938"
}
]
}
]
}
] ,
2024-09-12 18:03:19 +00:00
"references" : [
{
"url" : "https://gitlab.com/gitlab-org/gitlab/-/issues/464044" ,
2024-09-14 16:03:15 +00:00
"source" : "cve@gitlab.com" ,
"tags" : [
"Broken Link"
]
2024-09-12 18:03:19 +00:00
} ,
{
"url" : "https://hackerone.com/reports/2520722" ,
2024-09-14 16:03:15 +00:00
"source" : "cve@gitlab.com" ,
"tags" : [
"Permissions Required"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2024-09-12 18:03:19 +00:00
}
]
}