Gitlab · Gitlab Ce/Ee · CVE-2024-5528
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions prior to 16.11.6
GitLab CE/EE versions 17.0 through 17.0.3
GitLab CE/EE versions 17.1 through 17.1.1
**Description**
An issue was discovered in GitLab CE/EE which allows a subdomain takeover in GitLab Pages.
**Recommendations**
For GitLab CE/EE versions prior to 16.11.6, update to version 16.11.6 or later to resolve the issue.
For GitLab CE/EE versions 17.0 through 17.0.3, update to version 17.0.4 or later to resolve the issue.
For GitLab CE/EE versions 17.1 through 17.1.1, update to version 17.1.2 or later to resolve the issue.