CVE-2024-4660 is a high-severity vulnerability in GitLab EE, affecting versions 11.2 through 17.1.6, 17.2 through 17.2.4, and 17.3 through 17.3.1. This flaw allows an unauthenticated guest user to read the source code of private projects by leveraging group templates. The CVSS score of 7.5 indicates a high impact on confidentiality with low attack complexity and no user interaction required. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including a critical patch release from GitLab. Organizations using affected GitLab EE versions should prioritize patching to mitigate the risk of unauthorized source code disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.2.0, < 17.1.7CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.2.0, < 17.2.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.3.0, < 17.3.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 11.2, < 17.1.7CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 17.2, < 17.2.5CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.