CVE-2024-11129

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-11129
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11129.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11129
Aliases
Published
2025-04-10T13:02:48.148Z
Modified
2025-12-05T03:53:45.261352Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Generation of Error Message Containing Sensitive Information in GitLab
Details

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted searches with sensitive keywords to get the count of issues containing the searched term."

Database specific
{
    "cwe_ids": [
        "CWE-209"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11129.json",
    "cna_assigner": "GitLab"
}
References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "17.1"
        },
        {
            "fixed": "17.8.7"
        }
    ]
}
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "17.9"
        },
        {
            "fixed": "17.9.6"
        }
    ]
}
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "17.10"
        },
        {
            "fixed": "17.10.4"
        }
    ]
}

Affected versions

v17.*

v17.10.0-ee
v17.10.1-ee
v17.10.2-ee
v17.10.3-ee
v17.9.0-ee
v17.9.1-ee
v17.9.2-ee
v17.9.3-ee
v17.9.4-ee
v17.9.5-ee

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11129.json"