Home

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained in GraphQL logs.

PUBLISHED Reserved 2024-12-05 | Published 2024-12-12 | Updated 2024-12-12 | Assigner GitLab




MEDIUM: 4.0CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-532: Insertion of Sensitive Information into Log File

Product status

Default status
unaffected

11.0 (semver) before 17.4.6
affected

17.5 (semver) before 17.5.4
affected

17.6 (semver) before 17.6.2
affected

Credits

This issue was discovered internally by GitLab team member [Radamanthus Batnag](https://gitlab.com/radbatnag). finder

References

gitlab.com/gitlab-org/gitlab/-/issues/475211 (GitLab Issue #475211) issue-tracking permissions-required

cve.org (CVE-2024-12292)

nvd.nist.gov (CVE-2024-12292)

Download JSON