PT-2024-1901 · Gitlab · Gitlab Ce/Ee+1
Drew Blessing
·
Published
2024-02-15
·
Updated
2024-10-03
·
CVE-2024-1525
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 16.1 through 16.7.5
GitLab CE/EE versions 16.8 through 16.8.2
GitLab CE/EE versions 16.9 through 16.9.0
Description
An issue has been discovered affecting GitLab CE/EE, where under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP. This is related to insufficient access restriction in the LDAP authentication implementation. The issue may allow a remote attacker to reset the password of an arbitrary user and gain access to the system.
Recommendations
For GitLab CE/EE versions 16.1 through 16.7.5, update to version 16.7.6 or later.
For GitLab CE/EE versions 16.8 through 16.8.2, update to version 16.8.3 or later.
For GitLab CE/EE versions 16.9 through 16.9.0, update to version 16.9.1 or later.
Exploit
Fix
Improper Access Control
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee