CVE-2024-4660
GitLab vulnerability analysis and mitigation

Overview

A security vulnerability (CVE-2024-4660) was discovered in GitLab Enterprise Edition (EE) affecting versions from 11.2 before 17.1.7, versions from 17.2 before 17.2.5, and versions from 17.3 before 17.3.2. The vulnerability allows guest users to read the source code of private projects by exploiting group templates functionality (GitLab Release, NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. The issue stems from improper access control mechanisms in GitLab's group templates feature, where guest users could bypass intended restrictions to access private project source code. The vulnerability is classified under CWE-862 (Missing Authorization) (NVD).

Impact

The primary impact of this vulnerability is the potential disclosure of sensitive information. Guest users can exploit this flaw to read the complete source code of private projects that they should not have access to, potentially exposing proprietary code and sensitive business logic (GitLab Issue).

Mitigation and workarounds

GitLab has addressed this vulnerability in versions 17.1.7, 17.2.5, and 17.3.2. Organizations are strongly advised to upgrade to these patched versions immediately. GitLab.com has already been updated with the security fix (GitLab Release).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-7449MEDIUM6.5
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
NoYesNov 26, 2025
CVE-2025-12653MEDIUM6.5
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesNov 26, 2025
CVE-2024-9183MEDIUM6.4
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesDec 05, 2025
CVE-2025-13611MEDIUM5.3
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesNov 26, 2025
CVE-2025-6195MEDIUM4.3
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesNov 26, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management