Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vexinon

#46787of 53,630
5.4Total CVSS
Vulnerabilities · 1
PT-2024-5515
5.4
2024-08-07
Gitlab · Gitlab Ce/Ee · CVE-2024-4784
**Name of the Vulnerable Software and Affected Versions** GitLab EE versions 16.7 through 17.0.5 GitLab EE versions 17.1 through 17.1.3 GitLab EE versions 17.2 through 17.2.1 **Description** The issue is related to the bypassing of authentication in GitLab due to the lack of a request for re-entering a password. This can allow a remote attacker to bypass security restrictions. The vulnerability is associated with the approval of a policy without requiring password re-entry. **Recommendations** For GitLab EE versions 16.7 through 17.0.5, update to version 17.0.6 or later. For GitLab EE versions 17.1 through 17.1.3, update to version 17.1.4 or later. For GitLab EE versions 17.2 through 17.2.1, update to version 17.2.2 or later.