Loading HuntDB...

GHSA-vfph-fvw4-j4xp

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

Related CVEs

Key Information

GHSA ID
GHSA-vfph-fvw4-j4xp
Published
September 26, 2024 9:31 AM
Last Modified
September 26, 2024 9:31 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.