CVE-2024-12380
CVE-2024-12380
Título es
CVE-2024-12380
Jue, 13/03/2025 – 06:15
Tipo
CWE-209
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-12380
Descripción en
An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.
13/03/2025
13/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
4.40
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://gitlab.com/gitlab-org/gitlab/-/issues/508557
https://hackerone.com/reports/2868951
Enviar en el boletín
Off
