PT-2024-21894 · Gitlab · Gitlab

0Xn3Va

·

Published

2024-09-12

·

Updated

2024-09-16

·

CVE-2024-2743

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab-EE versions 13.3 through 17.1.7 GitLab-EE versions 17.2 through 17.2.5 GitLab-EE versions 17.3 through 17.3.2
Description An issue was discovered in GitLab-EE that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables. This issue affects versions starting with 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2.
Recommendations For GitLab-EE versions 13.3 through 17.1.7, update to version 17.1.7 or later to resolve the issue. For GitLab-EE versions 17.2 through 17.2.5, update to version 17.2.5 or later to resolve the issue. For GitLab-EE versions 17.3 through 17.3.2, update to version 17.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the DAST scan feature until a patch is available.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2024-2743
CVE-2024-2743

Affected Products

Gitlab