{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-12380","assignerOrgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","state":"PUBLISHED","assignerShortName":"GitLab","dateReserved":"2024-12-09T18:30:48.648Z","datePublished":"2025-03-13T05:56:14.642Z","dateUpdated":"2025-03-14T14:35:18.525Z"},"containers":{"cna":{"title":"Generation of Error Message Containing Sensitive Information in GitLab","descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information."}],"affected":[{"vendor":"GitLab","product":"GitLab","repo":"git://git@gitlab.com:gitlab-org/gitlab.git","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"versions":[{"version":"11.5","status":"affected","lessThan":"17.7.7","versionType":"semver"},{"version":"17.8","status":"affected","lessThan":"17.8.5","versionType":"semver"},{"version":"17.9","status":"affected","lessThan":"17.9.2","versionType":"semver"}],"defaultStatus":"unaffected"}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-209: Generation of Error Message Containing Sensitive Information","cweId":"CWE-209","type":"CWE"}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/508557","name":"GitLab Issue #508557","tags":["issue-tracking","permissions-required"]},{"url":"https://hackerone.com/reports/2868951","name":"HackerOne Bug Bounty Report #2868951","tags":["technical-description","exploit","permissions-required"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM"}}],"solutions":[{"lang":"en","value":"Upgrade to version 17.9.2, 17.8.5, 17.7.7"}],"credits":[{"lang":"en","value":"Thanks [sigitsetiawansss](https://hackerone.com/sigitsetiawansss) for reporting this vulnerability through our HackerOne bug bounty program","type":"finder"}],"providerMetadata":{"orgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","shortName":"GitLab","dateUpdated":"2025-03-13T05:56:14.642Z"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-03-14T14:32:51.742963Z","id":"CVE-2024-12380","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-03-14T14:35:18.525Z"}}]}}