An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2024-06-26T23:31:35.425Z

Updated: 2024-06-26T23:31:35.425Z

Reserved: 2024-03-29T23:30:45.826Z


Link: CVE-2024-3115

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-27T00:15:11.190

Modified: 2024-06-27T12:47:19.847


Link: CVE-2024-3115

JSON object: View

cve-icon Redhat Information

No data.

CWE