CVE-2024-10240 | GitLab Enterprise Edition up to 17.3.6/17.4.3/17.5.1 Private Project exposure of sensitive system information to an unauthorized control sphere (Issue 493188 / Nessus ID 211882)
A vulnerability was found in GitLab Enterprise Edition up to 17.3.6/17.4.3/17.5.1 and classified as problematic. Affected by this issue is some unknown functionality of the component Private Project Handler. The manipulation leads to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is handled as CVE-2024-10240. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.