GitLab CE
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 17.4, < 17.5.5
- >= 17.6, < 17.6.3
- >= 17.7, < 17.7.1
A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) in versions 17.4 prior to 17.5.5, 17.6 prior to 17.6.3, and 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been inadvertently logged during specific API requests, potentially exposing them in the GitLab logs.
This vulnerability could lead to unauthorized access token exposure in GitLab logs, allowing for potential misuse of the tokens.
GitLab has released patch versions 17.7.1, 17.6.3, and 17.5.5, which address this vulnerability. Users are strongly advised to upgrade to one of these versions immediately. Instructions for updating GitLab can be found on the GitLab update page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.