An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2024-06-26T23:31:25.425Z

Updated: 2024-06-27T17:37:19.509Z

Reserved: 2024-04-18T16:02:36.516Z


Link: CVE-2024-3959

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-27T00:15:11.420

Modified: 2024-06-27T12:47:19.847


Link: CVE-2024-3959

JSON object: View

cve-icon Redhat Information

No data.

CWE