« Back to list

CVE-2024-5435

Status: ModifiedMedium (6.5)—

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-5435",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-5435",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-12T17:25:05.825878Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@gitlab.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@gitlab.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
          ],
          "repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
          "vendor": "GitLab",
          "product": "GitLab",
          "versions": [
            {
              "status": "affected",
              "version": "15.10",
              "lessThan": "17.1.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "17.2",
              "lessThan": "17.2.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "17.3",
              "lessThan": "17.3.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-09-12T17:15:05.147",
  "references": [
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/464044",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://hackerone.com/reports/2520722",
      "tags": [
        "Permissions Required"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@gitlab.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-209"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-209"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema en GitLab EE/CE que afecta a todas las versiones desde la 15.10 hasta la 17.1.7, todas las versiones desde la 17.2 hasta la 17.2.5 y todas las versiones desde la 17.3 hasta la 17.3.2, que revelarán la contraseña del usuario desde la configuración del espejo del repositorio."
    }
  ],
  "lastModified": "2026-06-17T08:15:56.707",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABF7770C-12E5-496B-8D5F-F6E55E610AA8",
              "versionEndExcluding": "17.1.7",
              "versionStartIncluding": "15.10.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9EB56F1-6DB6-45C7-BD1B-B7B28A15B291",
              "versionEndExcluding": "17.1.7",
              "versionStartIncluding": "15.10.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DE9BFF3-C056-4146-A762-E34D60E10EDE",
              "versionEndExcluding": "17.2.5",
              "versionStartIncluding": "17.2.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F428DA1-FB1C-4B14-A1E1-65177E7F4B10",
              "versionEndExcluding": "17.2.5",
              "versionStartIncluding": "17.2.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2F29B41-64CF-4CEF-8EDF-BBDBA2FFE8C1",
              "versionEndExcluding": "17.3.2",
              "versionStartIncluding": "17.3.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "145E52CC-F503-446E-A760-1C01753DA938",
              "versionEndExcluding": "17.3.2",
              "versionStartIncluding": "17.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@gitlab.com"
}