PoC Index

CVE-2024-10043

LOW 3.1EPSS 0.4%

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions starting from 17.6 before 17.6.2, that allows group users to view confidential incident title through the Wiki History Diff feature, potentially leading to information disclosure.

CVSS v3.1
3.1 LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.45% chance of exploitation in the next 30 days, 37th percentile
Published
2024-12-12

Proof-of-concept exploits (2)

References

Related